Skip to content

Update Role Definition (Azure RBAC)

Azure

Update Role Definition (Azure RBAC)

service: Azure - Authorization
techniques:

Event

Updates an existing custom Azure RBAC permission definition. Actions and DataActions cover different permission planes; NotActions/NotDataActions subtract from this role’s grants and are not deny assignments. AssignableScopes controls where the role may be assigned; actual role-assignment scopes determine where a principal receives access.

Security Context

Unauthorized changes can expand permissions for existing assignees (contextual T1098.003). Expanding AssignableScopes does not expand existing assignment scopes. Wildcard Actions is broad control-plane authority within applicable assignments, not automatic tenant-wide access or every data-plane permission. Approved role maintenance uses the same operation.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Authorization/roleDefinitions/write. This page’s title is a catalog label for the ARM operation, not the similarly named Entra RoleManagement audit activity. Creation and update share the same operation name; use result, resource history, and prior state to distinguish them. Request/response bodies are not guaranteed in Activity Log exports.

Key Fields

FieldInvestigation value
operationName.value, resourceIdARM role-definition write operation and definition ID.
properties.requestbody, properties.responseBodyDefinition if included; payload presence is not guaranteed.
status, correlationId, operationIdRecorded result and related operation records.

What to Investigate

  1. Confirm the recorded outcome and match the initiating identity, target, and timing to an approved change.
  2. Recover the prior and resulting definitions and compare all permission arrays and assignment eligibility scopes.
  3. Enumerate actual role assignments, their scopes, conditions, and applicable deny assignments; do not infer effective access from the role name.
  4. Correlate role assignments and subsequent resource operations before claiming escalation or data theft.

Sample Event

Synthetic scenario. The sample submits wildcard control-plane Actions and a subscription in AssignableScopes. It contains no prior definition or assignment inventory, so subscription-wide access for existing holders is not established.

Exact field presence, target ordering, modified-property names, and payload serialization remain unverified against captured logs. Treat these examples as illustrations, not guaranteed schemas or complete change histories.

{
"authorization": {
"action": "Microsoft.Authorization/roleDefinitions/write",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleDefinitions/50000000-0000-4000-8000-000011101110"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "rdUpd231ExampleUtid01",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100100000",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100100001",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T18:21:04.5128072Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100111100",
"operationName": {
"value": "Microsoft.Authorization/roleDefinitions/write",
"localizedValue": "Update role definition"
},
"resourceGroupName": "",
"resourceProviderName": {
"value": "Microsoft.Authorization",
"localizedValue": "Microsoft.Authorization"
},
"resourceType": {
"value": "Microsoft.Authorization/roleDefinitions",
"localizedValue": "Microsoft.Authorization/roleDefinitions"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleDefinitions/50000000-0000-4000-8000-000011101110",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T18:21:05.1288014Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleDefinitions/50000000-0000-4000-8000-000011101110",
"message": "Microsoft.Authorization/roleDefinitions/write",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001",
"requestbody": "{\"name\":\"50000000-0000-4000-8000-000011101110\",\"properties\":{\"roleName\":\"Demiguise-MLOps-Operator\",\"description\":\"ML pipeline operator role\",\"assignableScopes\":[\"/subscriptions/20000000-0000-4000-8000-000000000001\"],\"permissions\":[{\"actions\":[\"*\"],\"notActions\":[],\"dataActions\":[],\"notDataActions\":[]}]}}"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation Persistence

Techniques:
  • T1098.003 — Additional Cloud Roles — An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.