TrustPolicy
Who may assume/impersonate a role/SA.
class: Policy derivation-only - no collection recipe
Realizing resources
This type has no collection recipe - it appears only as the endpoint of derived edges.
As edge target
Exposure sites
None.
Rules that touch TrustPolicy 12
The B2C IEF Keyset Administrator can replace the signing keyset used by custom policies, enabling token forgery for all relying party applications.
azure
CanModifyTrustB2C IEF Policy Administrator or Global Admin can upload/replace custom policy XML, effectively reconfiguring the entire authentication and federation pipeline.
azure
CanModifyConfigurationA principal who can write B2C custom policy XML can inject a Technical Profile trusting an attacker-controlled OIDC/SAML IdP.
azure
CanModifyTrustA customer principal with Microsoft.ManagedServices/registrationDefinitions/write can modify Lighthouse trust anchors (authorizations list, managing tenant).
azure
CanModifyTrustCreating or updating a WIF pool provider lets a principal add/loosen the trust to an attacker-controlled external IdP.
gcp
CanModifyTrust