Lab 04 — Azure Privilege Escalation Assessment
Mission Information
Section titled “Mission Information”Objective
Section titled “Objective”Perform an authorised security assessment of Azure Identity and Access Management (IAM) to identify privilege escalation opportunities, excessive permissions, misconfigured role assignments, and identity-related security risks.
Difficulty
Section titled “Difficulty”Intermediate
Estimated Time
Section titled “Estimated Time”90–120 Minutes
Career Alignment
Section titled “Career Alignment”- Cloud Penetration Tester
- Cloud Security Engineer
- Red Team Operator
- Security Consultant
Business Scenario
Section titled “Business Scenario”You are working as a Cloud Penetration Tester at CloudNova Technologies.
A financial services customer has requested an identity-focused penetration test of their Microsoft Azure environment.
The organisation recently migrated to Microsoft Entra ID and wants to verify that administrative permissions, role assignments, managed identities, and service principals follow the principle of least privilege.
Your engagement is limited to identifying privilege escalation opportunities and documenting security findings without making destructive changes to the production environment.
Learning Objectives
Section titled “Learning Objectives”By completing this lab you will be able to:
- Review Microsoft Entra ID identities.
- Assess Azure RBAC assignments.
- Identify excessive permissions.
- Evaluate managed identities.
- Review service principal permissions.
- Identify privilege escalation paths.
- Validate least privilege implementation.
- Produce professional assessment documentation.
Prerequisites
Section titled “Prerequisites”Students should complete:
- Module 01 — Azure Offensive Security Foundations
- Lesson 02 — Microsoft Azure Architecture
- Lesson 03 — Microsoft Entra ID Fundamentals
- Lesson 04 — Azure Resource Manager
- Lesson 05 — Azure Networking Fundamentals
Lab Environment
Section titled “Lab Environment”Azure Resources
Section titled “Azure Resources”- Microsoft Entra ID
- Azure Subscription
- Resource Groups
- Azure RBAC
- Managed Identities
- Service Principals
- Azure Portal
- Azure CLI
- Azure PowerShell
Assessment Scope
Section titled “Assessment Scope”Review the following components:
- Users
- Groups
- Administrative roles
- Azure RBAC
- Managed Identities
- Service Principals
- Privileged accounts
- Conditional Access overview
- Privileged Identity Management (where enabled)
Lab Tasks
Section titled “Lab Tasks”Task 01 — Review Microsoft Entra ID Users
Section titled “Task 01 — Review Microsoft Entra ID Users”Review:
- User accounts
- Administrative accounts
- Guest accounts
- Disabled accounts
- Emergency access accounts
Document any security observations.
Task 02 — Review Azure RBAC Assignments
Section titled “Task 02 — Review Azure RBAC Assignments”Review:
- Subscription roles
- Resource Group roles
- Resource roles
- Custom roles
- Built-in roles
Identify users or groups with excessive permissions.
Task 03 — Assess Administrative Roles
Section titled “Task 03 — Assess Administrative Roles”Review privileged roles including:
- Global Administrator
- Privileged Role Administrator
- User Administrator
- Security Administrator
- Owner
- Contributor
Determine whether least privilege has been implemented.
Task 04 — Review Managed Identities
Section titled “Task 04 — Review Managed Identities”Assess:
- System-assigned Managed Identities
- User-assigned Managed Identities
- Role assignments
- Resource permissions
Identify unnecessary or excessive access.
Task 05 — Review Service Principals
Section titled “Task 05 — Review Service Principals”Review:
- Application registrations
- Enterprise applications
- Client secrets
- Certificate authentication
- API permissions
Document any security concerns.
Task 06 — Identify Privilege Escalation Opportunities
Section titled “Task 06 — Identify Privilege Escalation Opportunities”Analyse the environment for potential privilege escalation paths resulting from:
- Excessive RBAC permissions
- Misconfigured administrative roles
- Over-privileged managed identities
- Service Principal permissions
- Resource ownership
- Delegated administration
Document each finding with supporting evidence.
Task 07 — Risk Assessment
Section titled “Task 07 — Risk Assessment”Assign a risk rating to every finding.
Categories:
- Critical
- High
- Medium
- Low
- Informational
Provide business impact and technical justification.
Task 08 — Executive Summary
Section titled “Task 08 — Executive Summary”Prepare a management summary including:
- Scope
- Methodology
- Identity posture
- Key findings
- Business impact
- Recommended remediation priorities
Expected Deliverables
Section titled “Expected Deliverables”At the end of this lab you should have:
- Identity assessment notes
- Azure RBAC review
- Administrative role review
- Managed Identity assessment
- Service Principal assessment
- Risk register
- Executive summary
- Technical findings
- Remediation recommendations
Validation Checklist
Section titled “Validation Checklist”You should be able to explain:
- Microsoft Entra ID architecture
- Azure RBAC model
- Administrative role hierarchy
- Managed Identity security
- Service Principal security
- Principle of Least Privilege
- Common privilege escalation risks
Real-World Skills Developed
Section titled “Real-World Skills Developed”After completing this lab you will gain experience in:
- Azure identity security assessments
- Enterprise IAM reviews
- RBAC validation
- Privileged access assessments
- Cloud penetration testing methodology
- Technical reporting
- Risk analysis
- Security consulting practices
Lab Summary
Section titled “Lab Summary”Congratulations!
You have completed an enterprise-style Azure Identity and Privilege Assessment using the GoHackersCloud Cloud Penetration Testing methodology.
This lab reflects the identity review activities commonly performed during authorised cloud penetration testing engagements and security consulting projects.
Next Lab
Section titled “Next Lab”➡️ Lab 05 — Enterprise Azure Cloud Penetration Test
In the next lab, you will perform a comprehensive Azure cloud security assessment by combining reconnaissance, identity analysis, networking, compute, storage, monitoring, and reporting into a complete enterprise penetration testing engagement.