logo

Azure Privilege Escalation via Service Principal Abuse

ID: 517c6256-1b4e-53e3-8986-27736cf8e08f

STIX ID: report--517c6256-1b4e-53e3-8986-27736cf8e08f

Feed Name: SpecterOps Blog

Date Published: 2021-10-12

Date Updated: 2026-04-30

Author: Andy Robbins

...
...

The report details an Azure AD privilege-escalation technique where users with roles such as Application Administrator can add credentials to service principals that hold high-privilege roles (e.g., Privileged Role Administrator or Global Administrator), enabling escalation to tenant-wide admin rights. It contrasts Azure’s built‑in password reset protections for Global Admin users with the lack of equivalent safeguards for service principals, maps the attack path, and recommends mitigations: auditing and minimizing privileged roles on service principals, reviewing app owners and app-scoped role assignments, and limiting who can manage application credentials. It also advocates for Microsoft to extend its safety mechanisms to protect privileged service principals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.