Skip to content

Lab 04 — Azure Privilege Escalation Assessment

Perform an authorised security assessment of Azure Identity and Access Management (IAM) to identify privilege escalation opportunities, excessive permissions, misconfigured role assignments, and identity-related security risks.


Intermediate


90–120 Minutes


  • Cloud Penetration Tester
  • Cloud Security Engineer
  • Red Team Operator
  • Security Consultant

You are working as a Cloud Penetration Tester at CloudNova Technologies.

A financial services customer has requested an identity-focused penetration test of their Microsoft Azure environment.

The organisation recently migrated to Microsoft Entra ID and wants to verify that administrative permissions, role assignments, managed identities, and service principals follow the principle of least privilege.

Your engagement is limited to identifying privilege escalation opportunities and documenting security findings without making destructive changes to the production environment.


By completing this lab you will be able to:

  • Review Microsoft Entra ID identities.
  • Assess Azure RBAC assignments.
  • Identify excessive permissions.
  • Evaluate managed identities.
  • Review service principal permissions.
  • Identify privilege escalation paths.
  • Validate least privilege implementation.
  • Produce professional assessment documentation.

Students should complete:

  • Module 01 — Azure Offensive Security Foundations
  • Lesson 02 — Microsoft Azure Architecture
  • Lesson 03 — Microsoft Entra ID Fundamentals
  • Lesson 04 — Azure Resource Manager
  • Lesson 05 — Azure Networking Fundamentals

  • Microsoft Entra ID
  • Azure Subscription
  • Resource Groups
  • Azure RBAC
  • Managed Identities
  • Service Principals
  • Azure Portal
  • Azure CLI
  • Azure PowerShell

Review the following components:

  • Users
  • Groups
  • Administrative roles
  • Azure RBAC
  • Managed Identities
  • Service Principals
  • Privileged accounts
  • Conditional Access overview
  • Privileged Identity Management (where enabled)

Task 01 — Review Microsoft Entra ID Users

Section titled “Task 01 — Review Microsoft Entra ID Users”

Review:

  • User accounts
  • Administrative accounts
  • Guest accounts
  • Disabled accounts
  • Emergency access accounts

Document any security observations.


Review:

  • Subscription roles
  • Resource Group roles
  • Resource roles
  • Custom roles
  • Built-in roles

Identify users or groups with excessive permissions.


Review privileged roles including:

  • Global Administrator
  • Privileged Role Administrator
  • User Administrator
  • Security Administrator
  • Owner
  • Contributor

Determine whether least privilege has been implemented.


Assess:

  • System-assigned Managed Identities
  • User-assigned Managed Identities
  • Role assignments
  • Resource permissions

Identify unnecessary or excessive access.


Review:

  • Application registrations
  • Enterprise applications
  • Client secrets
  • Certificate authentication
  • API permissions

Document any security concerns.


Task 06 — Identify Privilege Escalation Opportunities

Section titled “Task 06 — Identify Privilege Escalation Opportunities”

Analyse the environment for potential privilege escalation paths resulting from:

  • Excessive RBAC permissions
  • Misconfigured administrative roles
  • Over-privileged managed identities
  • Service Principal permissions
  • Resource ownership
  • Delegated administration

Document each finding with supporting evidence.


Assign a risk rating to every finding.

Categories:

  • Critical
  • High
  • Medium
  • Low
  • Informational

Provide business impact and technical justification.


Prepare a management summary including:

  • Scope
  • Methodology
  • Identity posture
  • Key findings
  • Business impact
  • Recommended remediation priorities

At the end of this lab you should have:

  • Identity assessment notes
  • Azure RBAC review
  • Administrative role review
  • Managed Identity assessment
  • Service Principal assessment
  • Risk register
  • Executive summary
  • Technical findings
  • Remediation recommendations

You should be able to explain:

  • Microsoft Entra ID architecture
  • Azure RBAC model
  • Administrative role hierarchy
  • Managed Identity security
  • Service Principal security
  • Principle of Least Privilege
  • Common privilege escalation risks

After completing this lab you will gain experience in:

  • Azure identity security assessments
  • Enterprise IAM reviews
  • RBAC validation
  • Privileged access assessments
  • Cloud penetration testing methodology
  • Technical reporting
  • Risk analysis
  • Security consulting practices

Congratulations!

You have completed an enterprise-style Azure Identity and Privilege Assessment using the GoHackersCloud Cloud Penetration Testing methodology.

This lab reflects the identity review activities commonly performed during authorised cloud penetration testing engagements and security consulting projects.


➡️ Lab 05 — Enterprise Azure Cloud Penetration Test

In the next lab, you will perform a comprehensive Azure cloud security assessment by combining reconnaissance, identity analysis, networking, compute, storage, monitoring, and reporting into a complete enterprise penetration testing engagement.