ResourceGroup

Azure resource group / logical grouping scope.

class: AdministrativeBoundary

Realizing resources

azure azure

resourcescopeenumeraterequired permissions
azure:resources:resourcegroup subscription Microsoft.Resources/subscriptions/resourceGroups (list) Microsoft.Resources/subscriptions/resourceGroups/read

Exposure sites

None.

Rules that touch ResourceGroup 12

A principal with roleAssignments/write or Owner role can grant the Azure Kubernetes Service RBAC Cluster Admin role to any principal.
A customer principal with Microsoft.ManagedServices/registrationDefinitions/write can modify Lighthouse trust anchors (authorizations list, managing tenant).
A customer principal with Microsoft.ManagedServices/registrationAssignments/write can create/modify Lighthouse registrationAssignments - enable cross-tenant access.
azure CanModify
A managing-tenant ExternalPrincipal named in a resource-group-scoped Lighthouse authorization has CanAdminister over that resource group.
Contributor at a subscription/RG can create, modify, and delete resources under it, but cannot assign RBAC.
A principal who can delete the owning Blueprint/Managed-App or remove a deny-effect policy assignment can lift the guardrail suppressing inherited control edges.
Owner at a subscription or resource group controls that boundary (full actions incl. RBAC assignment).
azure Controls
User Access Administrator (or RBAC Administrator) at a scope can assign itself Owner - role-assignment privesc.
move · open · esc close