Skip to content

This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Azure, Microsoft Azure and Microsoft Defender for Cloud are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.

Glossary

Elevate access (elevateAccess)

A Global Administrator feature that grants User Access Administrator at root scope (/) over every Azure subscription and management group of the tenant.

Elevate access lets a Microsoft Entra Global Administrator assign themselves the User Access Administrator role at root scope /, and from there any role in any subscription or management group of the tenant. The operation is Microsoft.Authorization/elevateAccess/action.

Microsoft documents that the entries appear in the Entra directory audit logs and in the Directory Activity (tenant-level) Activity Log — not in per-subscription exports — and recommends removing the elevated access after use (Microsoft Learn). Threat actors such as Storm-0501 have used it.

See Azure role assignment abuse and elevateAccess.

This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Azure, Microsoft Azure and Microsoft Defender for Cloud are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.