Azure Add App Role Assignment To Service Principal
Grants a resource application role to a client service principal.
The adversary is trying to gain higher-level permissions.
Privilege Escalation consists of techniques that adversaries use to gain higher-level permissions on a system or network. Adversaries can often enter and explore a network with unprivileged access but require elevated permissions to follow through on their objectives. Common approaches are to take advantage of system weaknesses, misconfigurations, and vulnerabilities. Examples of elevated access include:
In cloud environments, privilege escalation frequently involves exploiting overly permissive IAM policies, assuming roles with broader permissions, or modifying permission boundaries. Adversaries may attach administrator policies to compromised identities, exploit trust relationships between accounts, or leverage service-linked roles to gain elevated access.
View Privilege Escalation on MITRE ATT&CK →Explore this tactic in the map.
Grants a resource application role to a client service principal.
Records completed creation of PIM role eligibility.
Adds a principal to a Microsoft Entra directory role.
Adds an owner to a Microsoft Entra application registration.
Adds an owner to a Microsoft Entra group.
Creates a custom Azure resource RBAC role definition.
Adds a role binding through a resource-specific IAM policy update.
Adds a statement to a Lambda resource-based policy.
Adds one IAM role to an existing instance profile.
Adds an IAM user to a group, changing the policies that apply to the user.
Associates an instance profile with a running or stopped EC2 instance.
Returns temporary security credentials for assuming an IAM role. Allows an entity (user, service, or account) to act with the role's permissions.
Exchanges a validated SAML assertion for temporary IAM role credentials.
Exchanges a web-identity token for temporary IAM role credentials.
Attaches a managed permissions policy to an IAM group.
Attaches a managed permissions policy to an IAM role.
Attaches a managed permissions policy to an IAM user.
Replaces the IAM allow policy on a Compute Engine persistent disk.
Changes a VM’s attached service account and access scopes.
Records consent to an application’s requested permissions.
Creates an EKS access entry for an existing IAM principal.
Creates a new long-term access key for an IAM user, enabling programmatic access to AWS services.
Creates a legacy AWS Glue development endpoint.
Creates an EC2 key pair and returns its private key to the API caller.
Creates a console password for an IAM user.
Registers an OIDC identity provider in IAM.
Creates a customer-managed IAM policy with an initial default version.
Creates a customer-managed policy version, optionally making it the operative version.
Creates an IAM role with a trust policy and optional role settings.
Registers SAML identity-provider metadata in IAM.
Creates an IAM role linked to a specific AWS service.
Creates a virtual MFA device that must be enabled separately for an IAM user.
Removes the permissions boundary on an IAM role, potentially changing effective access.
Deletes a named inline permissions policy from an IAM role.
Removes the permissions boundary on an IAM user, potentially changing effective access.
Deletes a named inline permissions policy from an IAM user.
Detaches a managed policy from an IAM role without deleting the policy.
Detaches a managed policy from an IAM user without deleting the policy.
Enables a disabled service account.
Requests a short-lived OAuth access token for a service account.
Requests a temporary authentication token for private Amazon ECR registries.
Issues temporary federated-user credentials using long-term IAM-user credentials.
Issues temporary credentials for an IAM user, optionally with MFA context.
Creates a user-managed service-account key.
Sets the IAM allow policy on a service account.
Updates a custom IAM role definition.
Records permission to attach a service account to a resource.
Identifies delegated service-account token generation.
Signs a JWT using a service account’s Google-managed key.
Registers an existing public key as an EC2 key pair.
Grants an Entra Global Administrator Azure User Access Administrator at root scope.
Creates or updates an Azure RBAC role assignment, granting a principal specific permissions on a resource or scope.
Updates membership of an Entra group that is not role-assignable.
Adds or updates credentials on an Entra service principal.
Changes access-policy entries for an Azure Key Vault.
Authorizes attaching an existing user-assigned managed identity to a resource.
An IAM permission checked when a caller assigns a role to an AWS service; not an API event.
Adds or replaces a named inline permissions policy on an IAM group.
Replaces the policy on a KMS key.
Sets or replaces the permissions boundary on an IAM role, potentially changing effective access.
Adds or replaces a named inline permissions policy on an IAM role.
Sets or replaces the permissions boundary on an IAM user, potentially changing effective access.
Adds or replaces a named inline permissions policy on an IAM user.
Replaces the instance profile associated with a running EC2 instance.
Selects an existing customer-managed IAM policy version as the operative version.
Records a Cloud Storage access-policy change; this example changes bucket IAM.
Updates a custom Azure resource RBAC role definition.
Replaces an IAM role trust policy, changing the conditions for assuming it.
Changes a Glue development endpoint’s keys, arguments, or libraries.
Updates a Lambda function’s unpublished configuration.