Azure Add App Role Assignment To Service Principal
Grants a resource application role to a client service principal.
The adversary is trying to maintain their foothold.
Persistence consists of techniques that adversaries use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access. Techniques used for persistence include any access, action, or configuration changes that let them maintain their foothold on systems, such as replacing or hijacking legitimate code or adding startup code.
In cloud environments, adversaries persist by creating new IAM users or roles, attaching policies that grant backdoor access, deploying long-lived API keys, or modifying identity federation settings. They may also create resources like Lambda functions or scheduled tasks that maintain their access even if initial credentials are revoked.
View Persistence on MITRE ATT&CK →Explore this tactic in the map.
Grants a resource application role to a client service principal.
Creates an application registration in Microsoft Entra ID.
Records completed creation of PIM role eligibility.
Adds an external workload trust to a Microsoft Entra application registration.
Adds a principal to a Microsoft Entra directory role.
Adds an owner to a Microsoft Entra application registration.
Adds an owner to a Microsoft Entra group.
Creates a custom Azure resource RBAC role definition.
Creates a tenant-local service principal in Microsoft Entra ID.
Creates a user object in Microsoft Entra ID.
Adds a role binding through a resource-specific IAM policy update.
Adds a statement to a Lambda resource-based policy.
Adds one IAM role to an existing instance profile.
Adds an IAM user to a group, changing the policies that apply to the user.
Records an administrator registering user authentication information.
Attaches a managed permissions policy to an IAM group.
Attaches a managed permissions policy to an IAM role.
Attaches a managed permissions policy to an IAM user.
Changes the calling IAM user’s console password.
Replaces the IAM allow policy on a Compute Engine persistent disk.
Replaces instance-level metadata on a Compute Engine VM.
Replaces project-wide Compute Engine metadata.
Records consent to an application’s requested permissions.
Creates an EKS access entry for an existing IAM principal.
Creates a new long-term access key for an IAM user, enabling programmatic access to AWS services.
Requests creation of an AWS Organizations member account.
Creates a Systems Manager State Manager association.
Creates an EC2 key pair and returns its private key to the API caller.
Creates a console password for an IAM user.
Registers an OIDC identity provider in IAM.
Creates a customer-managed IAM policy with an initial default version.
Creates a customer-managed policy version, optionally making it the operative version.
Creates an IAM role with a trust policy and optional role settings.
Registers SAML identity-provider metadata in IAM.
Creates an IAM user without automatically creating sign-in credentials.
Creates a virtual MFA device that must be enabled separately for an IAM user.
Deletes a named inline permissions policy from an IAM role.
Deletes a named inline permissions policy from an IAM user.
Deletes an unassigned virtual MFA device resource.
Detaches a managed policy from an IAM role without deleting the policy.
Detaches a managed policy from an IAM user without deleting the policy.
Records removal of a user’s per-user MFA requirement.
Enables a disabled service account.
Requests a temporary authentication token for private Amazon ECR registries.
Issues temporary federated-user credentials using long-term IAM-user credentials.
Issues temporary credentials for an IAM user, optionally with MFA context.
Creates a user-managed service-account key.
Sets the IAM allow policy on a service account.
Uploads a public key certificate for a service account.
Updates a custom IAM role definition.
Registers an existing public key as an EC2 key pair.
Invites an external identity to collaborate in a Microsoft Entra tenant.
Creates or updates an Azure RBAC role assignment, granting a principal specific permissions on a resource or scope.
Creates or updates an Azure Automation runbook webhook.
Updates membership of an Entra group that is not role-assignable.
Adds or updates credentials on an Entra service principal.
Changes access-policy entries for an Azure Key Vault.
Authorizes attaching an existing user-assigned managed identity to a resource.
Adds or replaces a named inline permissions policy on an IAM group.
Registers an ECR image manifest and associated tag after layer upload.
Adds or replaces a named inline permissions policy on an IAM role.
Creates or updates an EventBridge rule.
Adds or updates targets associated with an EventBridge rule.
Adds or replaces a named inline permissions policy on an IAM user.
Records an administrative password reset for a Microsoft Entra user.
Selects an existing customer-managed IAM policy version as the operative version.
Creates an HMAC key for a service account’s Cloud Storage XML API access.
Records a Cloud Storage access-policy change; this example changes bucket IAM.
Updates a custom Azure resource RBAC role definition.
Records changes to a user’s registered Entra authentication methods.
Sets an IAM access key to Active or Inactive.
Replaces an IAM role trust policy, changing the conditions for assuming it.
Updates the unpublished code of a Lambda function.
Updates a Lambda function’s unpublished configuration.
Updates an IAM user console password or password-reset requirement.
Imports an SSH public key into an OS Login profile.
Updates an existing OS Login SSH public-key record; the method is not audit-logged.