Subscription
Azure subscription - RBAC + billing boundary.
class: AdministrativeBoundary
Realizing resources
azure azure
| resource | scope | enumerate | required permissions |
|---|---|---|---|
azure:resources:subscription |
tenant | Microsoft.Resources/subscriptions (list) |
Microsoft.Resources/subscriptions/read |
As edge source
As edge target
Exposure sites
None.
Rules that touch Subscription 21
A confirmed active SNS subscription binds the topic to its consumer; every Publish invokes the consumer with the message payload.
aws
CanTriggerBatch account data-plane endpoint reachable by any key/token holder unless restricted to private endpoints.
azure
ExposedToAccountA principal that can CanExecuteAs the pipeline's service-connection identity, where that identity holds ARM Contributor/Owner at subscription scope, gains a foothold in that Azure subscription.
azure
CanEnterSubscriptionA secret credential for a principal in another subscription yields entry there.
azure
CanEnterSubscriptionAn API connection referencing a resource in a different subscription (same tenant) represents cross-subscription exposure.
azure
ExposedToAccountA customer principal with Microsoft.ManagedServices/registrationDefinitions/write can modify Lighthouse trust anchors (authorizations list, managing tenant).
azure
CanModifyTrustA customer principal with Microsoft.ManagedServices/registrationAssignments/write can create/modify Lighthouse registrationAssignments - enable cross-tenant access.
azure
CanModifyA managing-tenant ExternalPrincipal named in a subscription-scoped Lighthouse authorization has CanEnterSubscription into the customer subscription.
azure
CanEnterSubscriptionA managing-tenant principal delegated User Access Administrator (with allowDelegatedRoleAssignments: true) can assign roles in the customer subscription - subscription-scoped CanGrantPermission.
azure
CanGrantPermissionMoving a subscription under a management group where the attacker is Owner makes the attacker's MG-scoped RBAC inherit down and take over the subscription.
azure
CanTakeOwnershipAn identity with <resource>/privateEndpointConnections/write on a PaaS resource can approve a private endpoint connection from a different subscription. Approving such a connection records a cross-subscription trust: the resource owner has explicitly authorized a network connection from another subscription's VNet, extending the reach of that remote VNet across the subscription boundary.
azure
CrossAccountTrustAn Approved private endpoint connection from a different subscription records an authorization relationship: the resource owner (in the provider subscription) has approved a network connection from an external (consumer) subscription. This models the cross-subscription trust relationship established by the approval.
azure
CrossAccountTrustContributor at a subscription/RG can create, modify, and delete resources under it, but cannot assign RBAC.
azure
CanAdministerA subscription associated/transferred to a different Entra tenant is a boundary-crossing trust (rare, privileged).
azure
CrossTenantTrustA principal that controls or administers a subscription has a control-plane foothold inside it.
azure
CanEnterSubscriptionA principal who can delete the owning Blueprint/Managed-App or remove a deny-effect policy assignment can lift the guardrail suppressing inherited control edges.
azure
CanModifyPolicyOwner at a subscription or resource group controls that boundary (full actions incl. RBAC assignment).
azure
ControlsUser Access Administrator (or RBAC Administrator) at a scope can assign itself Owner - role-assignment privesc.
azure
CanGrantPermissionExecuting as the fleet MI grants whatever RBAC that MI holds.
azure
CanEnterSubscription