Subscription

Azure subscription - RBAC + billing boundary.

class: AdministrativeBoundary

Realizing resources

azure azure

resourcescopeenumeraterequired permissions
azure:resources:subscription tenant Microsoft.Resources/subscriptions (list) Microsoft.Resources/subscriptions/read

Exposure sites

None.

Rules that touch Subscription 21

A confirmed active SNS subscription binds the topic to its consumer; every Publish invokes the consumer with the message payload.
Batch account data-plane endpoint reachable by any key/token holder unless restricted to private endpoints.
A principal that can CanExecuteAs the pipeline's service-connection identity, where that identity holds ARM Contributor/Owner at subscription scope, gains a foothold in that Azure subscription.
A secret credential for a principal in another subscription yields entry there.
An API connection referencing a resource in a different subscription (same tenant) represents cross-subscription exposure.
A customer principal with Microsoft.ManagedServices/registrationDefinitions/write can modify Lighthouse trust anchors (authorizations list, managing tenant).
A customer principal with Microsoft.ManagedServices/registrationAssignments/write can create/modify Lighthouse registrationAssignments - enable cross-tenant access.
azure CanModify
A managing-tenant ExternalPrincipal named in a subscription-scoped Lighthouse authorization has CanEnterSubscription into the customer subscription.
A managing-tenant principal delegated User Access Administrator (with allowDelegatedRoleAssignments: true) can assign roles in the customer subscription - subscription-scoped CanGrantPermission.
Moving a subscription under a management group where the attacker is Owner makes the attacker's MG-scoped RBAC inherit down and take over the subscription.
An identity with <resource>/privateEndpointConnections/write on a PaaS resource can approve a private endpoint connection from a different subscription. Approving such a connection records a cross-subscription trust: the resource owner has explicitly authorized a network connection from another subscription's VNet, extending the reach of that remote VNet across the subscription boundary.
An Approved private endpoint connection from a different subscription records an authorization relationship: the resource owner (in the provider subscription) has approved a network connection from an external (consumer) subscription. This models the cross-subscription trust relationship established by the approval.
Contributor at a subscription/RG can create, modify, and delete resources under it, but cannot assign RBAC.
A subscription associated/transferred to a different Entra tenant is a boundary-crossing trust (rare, privileged).
A principal that controls or administers a subscription has a control-plane foothold inside it.
A principal who can delete the owning Blueprint/Managed-App or remove a deny-effect policy assignment can lift the guardrail suppressing inherited control edges.
Owner at a subscription or resource group controls that boundary (full actions incl. RBAC assignment).
azure Controls
User Access Administrator (or RBAC Administrator) at a scope can assign itself Owner - role-assignment privesc.
Executing as the fleet MI grants whatever RBAC that MI holds.
move · open · esc close