Marc Gonzalez AmoresandGitHub f2f340de83 Add applications.myOrganization/allProperties/update privesc technique
## Summary

Adds a new privilege escalation technique to the EntraID privesc page, covering `microsoft.directory/applications.myOrganization/allProperties/update`.

This permission is not present in any built-in role but commonly appears in custom roles delegated to application teams under the assumption that the `.myOrganization` subtype scopes the action to internal-only apps. Since `allProperties` includes `passwordCredentials` and `keyCredentials`, the permission is functionally equivalent to credential-injection capability against every single-tenant app in the tenant.

## Why this matters

The existing page already documents `applications/credentials/update`. The new section complements it by surfacing the custom-role-scoped variant, which is underdocumented and easy to miss during privileged-role audits, admins filter on built-in privileged roles and miss custom roles carrying this single action.

## Testing

The full attack chain was reproduced end-to-end in an isolated Microsoft 365 Business Premium trial tenant:

      1. Created a custom role with `applications.myOrganization/allProperties/update` as the only action.
      2. Assigned it to a non-privileged victim user.
      3. From the victim's session, ran the documented commands to inject a credential into a target single-tenant app and successfully authenticated as the application via `az login --service-principal`.

## References

  - https://learn.microsoft.com/entra/identity/role-based-access-control/custom-available-permissions
  - https://learn.microsoft.com/entra/identity/role-based-access-control/permissions-reference
  - https://learn.microsoft.com/graph/api/application-addpassword
2026-06-12 11:02:33 +02:00
f
2026-06-05 10:40:57 +02:00
f
2026-05-26 17:55:54 +02:00
2026-05-18 21:36:03 +02:00
f
2026-04-13 20:01:42 +02:00
f
2026-02-13 11:15:25 +01:00
f
2026-05-11 16:51:50 +02:00
f
2026-04-19 12:54:23 +02:00
f
2025-11-21 13:42:46 +01:00
t10
2025-01-09 09:31:45 +01:00

HackTricks Cloud

{{#include ./banners/hacktricks-training.md}}

Hacktricks logos & motion designed by @ppieranacho.

Run HackTricks Cloud Locally

# Download latest version of hacktricks cloud
git clone https://github.com/HackTricks-wiki/hacktricks-cloud

# Select the language you want to use
export LANG="master" # Leave master for English
# "af" for Afrikaans
# "de" for German
# "el" for Greek
# "es" for Spanish
# "fr" for French
# "hi" for Hindi
# "it" for Italian
# "ja" for Japanese
# "ko" for Korean
# "pl" for Polish
# "pt" for Portuguese
# "sr" for Serbian
# "sw" for Swahili
# "tr" for Turkish
# "uk" for Ukrainian
# "zh" for Chinese

# Run the docker container indicating the path to the hacktricks-cloud folder
docker run -d --rm --platform linux/amd64 -p 3377:3000 --name hacktricks_cloud -v $(pwd)/hacktricks-cloud:/app ghcr.io/hacktricks-wiki/hacktricks-cloud/translator-image bash -c "mkdir -p ~/.ssh && ssh-keyscan -H github.com >> ~/.ssh/known_hosts && cd /app && git checkout $LANG && git pull && MDBOOK_PREPROCESSOR__HACKTRICKS__ENV=dev mdbook serve --hostname 0.0.0.0"

Your local copy of HackTricks Cloud will be available at http://localhost:3377 after a minute.

Pentesting CI/CD Methodology

In the HackTricks CI/CD Methodology you will find how to pentest infrastructure related to CI/CD activities. Read the following page for an introduction:

pentesting-ci-cd-methodology.md

Pentesting Cloud Methodology

In the HackTricks Cloud Methodology you will find how to pentest cloud environments. Read the following page for an introduction:

pentesting-cloud-methodology.md

License & Disclaimer

Check them in:

HackTricks Values & FAQ

Github Stats

HackTricks Cloud Github Stats

{{#include ./banners/hacktricks-training.md}}

S
Description
No description provided
Readme
683 MiB
Languages
CSS 31.5%
JavaScript 26.4%
Python 23.2%
Handlebars 16.7%
Shell 1.1%
Other 1.1%