CanAdminister

Full control (admin/owner) over a resource - implies most other capabilities on it.

resource_control CONTROL nature: explicit walkable weight 1 high value
Identity  ── CanAdminister ──▸  *

Source types

Identity

Target types

*

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

natureexplicit

Rules that emit CanAdminister 58

appflow:* grants full administrative control over all AppFlow flows and connector profiles in scope.
awsderived
apprunner:* grants full control of the service.
awsderived
Full control over an Elastic Beanstalk application (elasticbeanstalk:* or the admin managed policy).
awsderived
azurederived
Full control of the registry (write + all sub-resource management).
azurederived
Microsoft.ContainerService/managedClusters/* grants full control of the cluster (create/update/delete/stop/rotate/upgradeNodeImageVersion/etc.).
azurederived
Full control of an Automation Account (Automation Contributor / Contributor / Owner).
azurederived
Full control of an ADF factory (Data Factory Contributor / Contributor / Owner).
azurederived
Full administrative control over a public Azure DNS zone (DNS Zone Contributor or equivalent): the principal can manage all record types, zone settings, and zone-level RBAC delegation (where Owner scope is held).
azurederived
Full administrative control over a private Azure DNS zone (Private DNS Zone Contributor or equivalent): the principal can manage all record types, zone settings, and VNet links.
azurederived
Full control of an Event Grid topic (EventGrid Contributor / Contributor / Owner).
azurederived
Full control of an Event Hubs namespace (Contributor / Owner / custom role with namespaces/write); subsumes send, receive, listkeys, and entity management.
azurederived
azurederived
Key Vault Administrator (data-plane vaults/* dataAction) fully controls the vault data plane.
azurederived
Owner/Contributor/Key Vault Contributor (control-plane vaults/write) fully controls the vault object.
azurederived
A managing-tenant ExternalPrincipal named in a resource-group-scoped Lighthouse authorization has CanAdminister over that resource group.
azurederived
Holding the Microsoft.Network/loadBalancers/* wildcard grants full control of a Standard Load Balancer.
azurederived
Holding Microsoft.Network/applicationGateways/* grants full control of an Application Gateway including routing rules, SSL certs, WAF policy, and backend pools.
azurederived
Full control of a Log Analytics workspace (Log Analytics Contributor / Contributor / Owner).
azurederived
Full control of a Logic App workflow (Logic App Contributor / Contributor / Owner).
azurederived
Owner at a management group scope administers that boundary; feeds can-control -> Controls -> subtree descent.
azurederived
Principal with the networkSecurityGroups/* wildcard (Network Contributor, Contributor, Owner) has full administrative control over the NSG.
azurederived
ARM write (redis/write) permission grants full control-plane administration: firewall rules, authentication settings, port configuration, managed identity, and deletion.
azurederived
regenerateKey/action allows rotating the Redis access keys, enabling session revocation and credential rotation for persistence. Treated as control capability.
azurederived
Full control of a Service Bus namespace (Contributor / Owner at namespace scope; NOT Service Bus Data Owner which lacks ARM write).
azurederived
Contributor at a subscription/RG can create, modify, and delete resources under it, but cannot assign RBAC.
azurederived
ARM Contributor/Owner on the Synapse workspace grants full control: create/delete pools, update settings, manage linked services, set AAD admin.
azurederived
azurederived
roles/artifactregistry.admin or roles/artifactregistry.repoAdmin grants full control over an Artifact Registry repository, including push, policy mutation, and deletion.
gcpderived
roles/deploymentmanager.admin grants full control of all DM resources - create, update, delete, and setIamPolicy on DM deployment objects.
gcpderived
Holding compute.loadBalancerAdmin-equivalent permissions (roles/compute.loadBalancerAdmin or roles/compute.networkAdmin / roles/compute.admin) grants full create/update/delete control over all Cloud Load Balancing resources: forwarding rules, target proxies, URL maps, backend services, NEGs, health checks, SSL certificates.
gcpderived
roles/source.admin grants full control over a CSR repository, including push, IAM policy mutation, and deletion - implies CanModifyCode, CanModifyPolicy, CanRead, and CanModifyConfiguration.
gcpderived
Principal with rds:ModifyDBCluster on the cluster resource ARN can administer the cluster: modify IAM auth settings, VPC security groups, parameter groups, and deletion protection.
awsexplicit
Wildcard permission on disks grants full control of the disk resource.
azureexplicit
Wildcard permission on snapshots grants full control of the snapshot resource.
azureexplicit
Write access to the AFD profile object (Microsoft.Cdn/profiles/*) grants full control: endpoints, origin groups, origins, security policies, WAF links, rule sets, and custom domains.
azureexplicit
Full ARM control of the AML workspace grants administrative authority over all compute, jobs, datastores, and linked services.
azureexplicit
azureexplicit
Principal with full control of the MI ARM object (Managed Identity Contributor / Contributor / Owner at scope) can administer the user-assigned identity resource.
azureexplicit
Write access to a private DNS zone object (Microsoft.Network/privateDnsZones/write) grants full administrative control: the identity can replace, delete, or recreate the zone entirely. This is higher-impact than record-level write because it includes zone deletion (DoS) and recreation with attacker-controlled records. Zone write subsumes record write (the can-control linchpin derives Controls from this).
azureexplicit
Write access to a private endpoint object (privateEndpoints/write) grants full control of that PE - NIC, DNS zone groups, and subnet placement - enabling the attacker to reconfigure where private traffic flows.
azureexplicit
azureexplicit
Write access to the Virtual WAN or Virtual Hub object (virtualWans/write or virtualHubs/write, both included in Network Contributor) grants full control of the vWAN topology, all hub connections, route tables, gateways, and routing policy.
azureexplicit
roles/cloudsql.admin (including cloudsql.instances.* permissions) grants full administrative control over Cloud SQL instances.
gcpexplicit
move · open · esc close