Skip to content
Threat Feed
medium advisory

Detection of Privileged Role Assignment to Azure Service Principals

This brief details the detection of potential privilege escalation in Azure Active Directory where attackers assign highly privileged roles to service principals to maintain persistent, elevated cloud access.

Adversaries targeting Azure Active Directory (now Microsoft Entra ID) environments often seek to establish persistence and escalate privileges by manipulating service principals. By assigning high-privilege roles to a compromised or attacker-controlled service principal, an actor can leverage the non-human identity to perform actions, exfiltrate data, or further compromise the cloud tenant without the need for interactive user credentials. This activity is a common technique used by groups like Lapsus$ to achieve long-term access. Detection requires monitoring O365 Universal Audit Logs for role assignment operations (e.g., 'Add member to role') where the target identity is a service principal rather than a standard user account. Defenders should correlate these assignments against a list of known privileged role templates to filter for critical escalation risks.

Attack Chain

  1. Attacker gains initial access to an Azure environment, potentially through a compromised user account with permission to modify identity configurations.
  2. Attacker discovers an existing service principal or creates a new one to serve as a backdoored identity.
  3. Attacker identifies a target privileged role in Azure AD (e.g., Global Administrator or Privileged Role Administrator).
  4. Attacker performs an 'Add member to role' operation via the Azure portal, CLI, or API, targeting the service principal identity.
  5. The O365 Universal Audit Log records the role assignment event including the Actor (initiator) and the ObjectId (target).
  6. The service principal assumes the new permissions, allowing the attacker to interact with cloud resources or Microsoft Graph API with elevated rights.
  7. Attacker uses the service principal to maintain persistence, bypassing conditional access policies or password rotation requirements associated with human users.

Impact

Successful exploitation allows attackers to gain full administrative control over an Azure tenant, facilitating data exfiltration, shadow administrator creation, and total compromise of managed cloud resources. This impact is significant for organizations relying on Azure for identity and infrastructure management.

Recommendation

Deploy detection logic to alert on role assignment operations targeting non-human entities.

  • Implement a monitoring pipeline for O365 Universal Audit Log events using the 'Add member to role' and 'Add eligible member to role' operations.
  • Maintain an up-to-date lookup table of 'privileged_azure_ad_roles' to compare against the 'object_id' reported in the audit logs.
  • Prioritize alerts where the Target category is 'ServicePrincipal' to filter out standard user modifications.
  • Use the provided drilldown searches in your SIEM to investigate the full scope of activity associated with the 'src_user' and 'user' identified in the event.

Immediate actions

Review existing O365 audit logging to ensure 'Add member to role' events are ingested.

Detection Engineering 48h

Threat Hunt

Identify all service principals currently assigned roles with Global Administrator or equivalent privileges.

T1098.003 high high confidence hunt now

Data: Azure AD/Entra ID Role Assignment logs

Mitigations

Review and remove unnecessary privileged role assignments from service principals.

immediate IT Operations

T1098.003