Azure Add App Role Assignment To Service Principal
Grants a resource application role to a client service principal.
An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...
View on MITRE ATT&CK →Grants a resource application role to a client service principal.
Records completed creation of PIM role eligibility.
Adds a principal to a Microsoft Entra directory role.
Creates a custom Azure resource RBAC role definition.
Adds a role binding through a resource-specific IAM policy update.
Replaces the IAM allow policy on a Compute Engine persistent disk.
Creates an IAM role with a trust policy and optional role settings.
Creates an IAM role linked to a specific AWS service.
Sets the IAM allow policy on a service account.
Grants an Entra Global Administrator Azure User Access Administrator at root scope.
Creates or updates an Azure RBAC role assignment, granting a principal specific permissions on a resource or scope.
Updates membership of an Entra group that is not role-assignable.
Records a Cloud Storage access-policy change; this example changes bucket IAM.
Updates a custom Azure resource RBAC role definition.