Azure Add App Role Assignment To Service Principal
Grants an application role to a service principal, allowing it to act with that role's permissions within the application.
An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...
View on MITRE ATT&CK →Grants an application role to a service principal, allowing it to act with that role's permissions within the application.
Adds a user as an eligible member for a privileged role in Azure PIM, allowing them to activate the role on demand.
Directly assigns a user or service principal to an Entra ID directory role, granting that role's permissions.
Creates a new custom Azure RBAC role definition with specified allowed and denied actions.
Adds an IAM policy binding to a GCP resource, granting a member (user, group, or service account) a specified role.
Creates a new IAM role with a trust policy that defines which principals are permitted to assume it.
Creates a service-linked IAM role that allows an AWS service to perform actions on your behalf.
Creates or updates an Azure RBAC role assignment, granting a principal specific permissions on a resource or scope.
Adds or removes members from an Entra ID security group or Microsoft 365 group.
Sets the IAM policy on a Cloud Storage bucket or object, controlling which principals can access it.
Modifies an existing custom Azure RBAC role definition, updating its allowed or denied actions.