ManagementGroup
Azure MG; hierarchical policy scope.
class: AdministrativeBoundary
Realizing resources
azure azure
| resource | scope | enumerate | required permissions |
|---|---|---|---|
azure:management:managementgroup |
tenant | Microsoft.Management/managementGroups (list) |
Microsoft.Management/managementGroups/read |
As edge source
As edge target
Exposure sites
None.
Rules that touch ManagementGroup 6
A Microsoft Entra Global Administrator can call elevateAccess to gain User Access Administrator at root scope (/), controlling the root management group and thus every subscription in the tenant.
Ability to write Azure Policy assignments/definitions at a management group scope lets a principal weaken or remove a deny-effect guardrail inherited by the subtree.
azure
CanModifyPolicyMoving a subscription under a management group where the attacker is Owner makes the attacker's MG-scoped RBAC inherit down and take over the subscription.
azure
CanTakeOwnershipOwner at a management group scope administers that boundary; feeds can-control -> Controls -> subtree descent.
azure
CanAdministerManagement-group write lets a principal reparent a subscription / child MG (move it into or out of an MG), altering which RBAC and guardrails it inherits.
azure
CanModifyConfigurationAbility to assign RBAC at a management group scope (Owner / User Access Administrator) is a boundary-scoped self-grant over the whole subtree.
azure
CanGrantPermission