Group

Membership container that grants inherited permissions.

class: Identity

Realizing resources

aws aws

resourcescopeenumeraterequired permissions
aws:iam:group global iam:ListGroups iam:ListGroups

gcp gcp

resourcescopeenumeraterequired permissions
gcp:cloudidentity:group global cloudidentity.groups.list cloudidentity.groups.list

azure azure

resourcescopeenumeraterequired permissions
azure:entra:group global msgraph:groups.list Group.Read.All

Rules that touch Group 13

Resetting the password of a domain-admin directory user yields privilege escalation to domain-admin access over all domain-joined resources.
elasticache:ModifyUserGroup can add an attacker-controlled ACL User to a User Group that is already attached to a Redis/Valkey cluster. The attacker then authenticates as that user to the cluster with the user's effective ACL permissions (which may include allcommands/allkeys for full access). This bypasses the AUTH token and grants data-plane access via the ACL user.
A service principal holding Group.ReadWrite.All, GroupMember.ReadWrite.All, or Directory.ReadWrite.All can add any principal (including itself) to any Entra group, inheriting that group's RBAC role assignments, Graph app role assignments, and any other entitlements the group carries.
Principal with cloudidentity.groups.memberships.create (or group Manager/Owner role) can add any principal - including itself - to the target group, inheriting its bound GCP IAM roles.
Principal with cloudidentity.groups.memberships.delete (or group Manager/Owner) can remove members from the target group, enabling member deprovisioning or audit-trail destruction.
move · open · esc close