NetSPI Details Azure Privilege-Escalation Risks and a Fixed Built-In Role

Summary
NetSPI explains how Azure RBAC permissions and ABAC conditions can create privilege-escalation paths, and reports that Microsoft removed role-assignment permissions from the Anyscale Platform Administrator built-in role.
Key points
- NetSPI’s permission-mapping research found that the Anyscale Platform Administrator built-in role allowed arbitrary role assignments and escalation to Owner because it lacked ABAC constraints.
- Microsoft removed the role’s role-assignment write and delete permissions after the issue was reported to MSRC.
- The researchers describe how a custom role containing role-assignment permissions could bypass a recommended ABAC condition on Owner or User Access Administrator; MSRC marked this behavior as by design.
- The article explains how Azure’s RBAC and ABAC permissions, conditions, scopes, and data-plane access affect privilege-escalation analysis.
- NetSPI used the ARM Role Definitions List API’s hasAllPermissions filter to map risky permissions to built-in and custom roles.
- The research notes that permissions such as Storage Account key listing can grant data access, even when included in roles intended for other services.
- The authors recommend reviewing all roles, applying least privilege, and assigning roles at the narrowest practical scope.
Article Details
- Attack Vectors
- A principal with a Portal-recommended ABAC condition on an Owner or User Access Administrator assignment could create a custom role containing Microsoft.Authorization/roleAssignments/write, then assign that role to themselves or another principal. The resulting unconstrained role would bypass the assignment's condition; MSRC closed the report as by design.
- The Anyscale Platform Administrator Role previously included unconstrained Microsoft.Authorization/roleAssignments/write and /delete permissions. Researchers reported that a principal assigned the role could grant Owner access. Microsoft subsequently removed those permissions.
- Microsoft.Storage/storageAccounts/listkeys/action can expose Storage Account Shared Access Keys, which provide data-plane access. Assignment scope determines how many Storage Accounts a principal could access.
- The article identifies VM run-command access, assignment of User Assigned Managed Identities, and access to supporting-service secrets as categories of potential privilege-escalation paths.
- Defensive Notes
- Review ABAC conditions alongside RBAC permissions when assessing a role's effective access; a condition on role-assignment writes does not necessarily constrain other privileged permissions.
- Review built-in and custom roles for unexpected permissions before assignment, apply least privilege, and assign roles at the narrowest practical scope.
- Logically segment workloads, including placing critical identity resources in a dedicated Subscription where appropriate.
MITRE ATT&CK
People
Andy RobbinsCited for prior Entra and Azure privilege-escalation research.Katie KnowlesCited for prior research on Azure secrets access and related topics.Ryan HausknechtCited as the creator of PowerZure and the Azure Threat Research Matrix, and for research on Virtual Machine and Storage Account attacks.Seth ArtCited for work on privilege-escalation pathfinding and the pathfinding.cloud project.
Vendors
Products
AzureAzure has been growing rapidly over the past few yearsAzure Machine Learning ServiceStorage Account access with Microsoft.Storage/storageAccounts/listkeys/action leads to compromise of Notebooks and Managed Identities in the Azure Machine Learning ServiceAzure PortalIf you have used the Azure Portal to assign a role recently, you may have noticed the “Conditions” tab that pops up when assigning privileged roles, like Owner.
Tools
Azure Threat Research MatrixHe also created the Azure Threat Research Matrix, which mapped Azure specific TTPs to MITRE ATT&CK like categories.AzureHoundThere are also a number of new and updated tools that give us insight into the Azure attack surface like AzureHound, ScEntra, Cirro, and ROADRecon.CirroThere are also a number of new and updated tools that give us insight into the Azure attack surface like AzureHound, ScEntra, Cirro, and ROADRecon.pathfinding.cloudCheck out that talk and his pathfinding.cloud project!PowerZureRyan Hausknecht created the PowerZure tool and has blogged on Virtual Machine and Storage Account attacks.ROADReconThere are also a number of new and updated tools that give us insight into the Azure attack surface like AzureHound, ScEntra, Cirro, and ROADRecon.ScEntraThere are also a number of new and updated tools that give us insight into the Azure attack surface like AzureHound, ScEntra, Cirro, and ROADRecon.