CanModifyTrust

Source can rewrite who may assume/impersonate the target - self-grant assumption.

identity_authz AUTHORIZATION nature: explicit walkable weight 1 high value
Identity  ── CanModifyTrust ──▸  Role, TrustPolicy, ServiceAccount, MachineIdentity

Source types

Identity

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

natureexplicit

Per-cloud

cloudpermissions / triggersnote
aws iam:UpdateAssumeRolePolicy
gcp iam.serviceAccounts.setIamPolicy
azure update federated credentials / SP owner

Rules that emit CanModifyTrust 22

Registering an attacker-controlled CA as a trust anchor lets the attacker mint certs that federate into any role trusting the Roles Anywhere service principal.
awsderived
Creating/updating a Roles Anywhere profile that lists a privileged role (with iam:PassRole) maps the attacker's cert to that role.
awsderived
A principal who can write B2C custom policy XML can inject a Technical Profile trusting an attacker-controlled OIDC/SAML IdP.
azurederived
The B2C IEF Keyset Administrator can replace the signing keyset used by custom policies, enabling token forgery for all relying party applications.
azurederived
A customer principal with Microsoft.ManagedServices/registrationDefinitions/write can modify Lighthouse trust anchors (authorizations list, managing tenant).
azurederived
A service principal holding Application.ReadWrite.All or Directory.ReadWrite.All can modify the trust configuration of any app registration by adding a federated identity credential (OIDC trust), allowing an attacker-controlled external issuer to obtain tokens as that app without a static secret.
azurederived
Workspace super-admin can authorize any service account for Domain-Wide Delegation (adding its OAuth2 client ID to the delegated clients list with chosen scopes), creating a new tenant-wide impersonation primitive.
gcpderived
Creating or updating a WIF pool provider lets a principal add/loosen the trust to an attacker-controlled external IdP.
gcpderived
setIamPolicy on a ServiceAccount lets a principal add/loosen the workloadIdentityUser binding that maps an external WIF subject to the SA.
gcpderived
opsworks:UpdateStack + iam:PassRole on the new service role swaps the identity OpsWorks operates as.
awsexplicit
move · open · esc close