Lab description
This lab contains 0 Azure resource(s), 2 assignment(s), and 1 enabled attack path(s).
Source: /home/runner/work/BadZure/BadZure/docs/labs/concepts/app-ownership.yml
This lab contains 0 Azure resource(s), 2 assignment(s), and 1 enabled attack path(s).
The organization contains 1 user(s), 0 group(s), 1 service principal(s), and 0 administrative unit(s).
| Object | Properties |
|---|---|
| jordan |
display name: Jordan mail nickname: jordan user principal name: jordan |
None
| Object | Properties |
|---|---|
| automation-app | display name: automation-app |
None
| Type | Source | Target | Properties |
|---|---|---|---|
| OWNS_APPLICATION | jordan | automation-app |
key: owns_privileged_app__a1 origin: attack_path |
| ASSIGNED_ENTRA_ROLE | automation-app | Global Administrator |
key: owns_privileged_app__a2 origin: attack_path role: Global Administrator |
None
None
None
None
None
None
None
None
None
A user owns an application that holds Global Administrator.
controlled principal 'automation-app' holds the target Entra role.
MITRE: T1078.004, T1098.001.
High-level Entra identity inventory with user, application service-principal, and managed-identity summaries, group structure, and administrative-unit membership counts.
Subscription and resource-group placement with visible inventory totals, resources grouped by type, and missing placement called out explicitly.
Generated assignment families, roles and permissions, summarized by principal type. Select an aggregate for counts and underlying references.
Legitimate configuration relationships that make this path possible.
Ordered attacker actions from initial access to the path objective.