CanTakeOwnership

Source can become owner (Azure SP/app owner, resource owner) and thereby self-grant control.

resource_control CONTROL nature: explicit walkable weight 1
Identity  ── CanTakeOwnership ──▸  *, ApplicationIdentity

Source types

Identity

Target types

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

natureexplicit

Rules that emit CanTakeOwnership 4

azurederived
Moving a subscription under a management group where the attacker is Owner makes the attacker's MG-scoped RBAC inherit down and take over the subscription.
azurederived
A service principal holding Application.ReadWrite.All can add itself as the owner of any app registration, granting it permanent owner-level control (credential addition, configuration change) independent of the original permission grant.
azurederived
move · open · esc close