ManagementGroup

Azure MG; hierarchical policy scope.

class: AdministrativeBoundary

Realizing resources

azure azure

resourcescopeenumeraterequired permissions
azure:management:managementgroup tenant Microsoft.Management/managementGroups (list) Microsoft.Management/managementGroups/read

Exposure sites

None.

Rules that touch ManagementGroup 6

A Microsoft Entra Global Administrator can call elevateAccess to gain User Access Administrator at root scope (/), controlling the root management group and thus every subscription in the tenant.
Ability to write Azure Policy assignments/definitions at a management group scope lets a principal weaken or remove a deny-effect guardrail inherited by the subtree.
Moving a subscription under a management group where the attacker is Owner makes the attacker's MG-scoped RBAC inherit down and take over the subscription.
Owner at a management group scope administers that boundary; feeds can-control -> Controls -> subtree descent.
Management-group write lets a principal reparent a subscription / child MG (move it into or out of an MG), altering which RBAC and guardrails it inherits.
Ability to assign RBAC at a management group scope (Owner / User Access Administrator) is a boundary-scoped self-grant over the whole subtree.
move · open · esc close