Skip to content
← LibraryTechnique entry
C-AZ-RBAC-OWNERPrivilege Escalation

Azure RBAC Owner Assignment

Microsoft.Authorization/roleAssignments/write on a scope lets the principal grant itself Owner — across subscription / RG / resource.

§ Where this technique fits

C-AZ-RBAC-OWNER is catalogued under the Privilege Escalation tactic of the offensive-security kill-chain. It appears in 3 approved dossiers in the registry, typically at step 4.7 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Azure VM RunCommand
    C-AZ-RUNCOMMAND-VM · Lateral Movement
    seen 1×
  2. 02
    Entra Application Persistence
    C-AZ-APP-PERSIST · Persistence
    seen 1×
  3. 03
    Valid Accounts
    T1078 · Initial Access
    seen 1×