Lab description
This lab contains 0 Azure resource(s), 3 assignment(s), and 1 enabled attack path(s).
Source: /home/runner/work/BadZure/BadZure/docs/labs/concepts/group-indirection.yml
This lab contains 0 Azure resource(s), 3 assignment(s), and 1 enabled attack path(s).
The organization contains 1 user(s), 1 group(s), 1 service principal(s), and 0 administrative unit(s).
| Object | Properties |
|---|---|
| robin |
display name: Robin mail nickname: robin user principal name: robin |
| Object | Properties |
|---|---|
| app-operators | display name: app-operators |
| Object | Properties |
|---|---|
| role-manager-app | display name: role-manager-app |
None
| Type | Source | Target | Properties |
|---|---|---|---|
| MEMBER_OF | robin | app-operators |
key: group_member_to_app_admin__a1 origin: attack_path |
| ASSIGNED_ENTRA_ROLE | app-operators | Application Administrator |
key: group_member_to_app_admin__a2 origin: attack_path role: Application Administrator |
| ASSIGNED_ENTRA_ROLE | role-manager-app | Global Administrator |
key: group_member_to_app_admin__a3 origin: attack_path role: Global Administrator |
None
None
None
None
None
None
None
None
None
A user inherits Application Administrator through group membership, takes over an app holding a privileged Graph permission, and escalates to Global Administrator.
controlled principal 'role-manager-app' holds the target Entra role.
MITRE: T1078.004, T1098.003, T1098.001.
High-level Entra identity inventory with user, application service-principal, and managed-identity summaries, group structure, and administrative-unit membership counts.
Subscription and resource-group placement with visible inventory totals, resources grouped by type, and missing placement called out explicitly.
Generated assignment families, roles and permissions, summarized by principal type. Select an aggregate for counts and underlying references.
Legitimate configuration relationships that make this path possible.
Ordered attacker actions from initial access to the path objective.