ResourceGroup
Azure resource group / logical grouping scope.
class: AdministrativeBoundary
Realizing resources
azure azure
| resource | scope | enumerate | required permissions |
|---|---|---|---|
azure:resources:resourcegroup |
subscription | Microsoft.Resources/subscriptions/resourceGroups (list) |
Microsoft.Resources/subscriptions/resourceGroups/read |
As edge source
As edge target
Exposure sites
None.
Rules that touch ResourceGroup 12
A principal with roleAssignments/write or Owner role can grant the Azure Kubernetes Service RBAC Cluster Admin role to any principal.
azure
CanGrantPermissionA customer principal with Microsoft.ManagedServices/registrationDefinitions/write can modify Lighthouse trust anchors (authorizations list, managing tenant).
azure
CanModifyTrustA customer principal with Microsoft.ManagedServices/registrationAssignments/write can create/modify Lighthouse registrationAssignments - enable cross-tenant access.
azure
CanModifyA managing-tenant ExternalPrincipal named in a resource-group-scoped Lighthouse authorization has CanAdminister over that resource group.
azure
CanAdministerContributor at a subscription/RG can create, modify, and delete resources under it, but cannot assign RBAC.
azure
CanAdministerA principal who can delete the owning Blueprint/Managed-App or remove a deny-effect policy assignment can lift the guardrail suppressing inherited control edges.
azure
CanModifyPolicyOwner at a subscription or resource group controls that boundary (full actions incl. RBAC assignment).
azure
ControlsUser Access Administrator (or RBAC Administrator) at a scope can assign itself Owner - role-assignment privesc.
azure
CanGrantPermission