BED-4887: AZResetPassword edge false positive on a role-assignable group. #1151
+62
−10
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Before creating AZResetPassword from an AZRole to an AZUser, make sure the user is not a member of a role assignable group.
Motivation and Context
This PR addresses: https://specterops.atlassian.net/browse/BED-4887
How Has This Been Tested?
Ingest SpecterDev.
Run pathfinding between
PARTNER TIER1 SUPPORT@SPECTEROPS DEVELOPMENT
andACHILES@SPECTERDEV.ONMICROSOFT.COM
You should get the following results (important part is that there is no AZPasswordReset edge directly between the two):
data:image/s3,"s3://crabby-images/2f350/2f350f84a73add1e0b44b48943e577168cb15f25" alt="Screenshot from 2025-02-19 16-58-16"
Prior to this fix, you would see the following:
data:image/s3,"s3://crabby-images/ac4aa/ac4aa667bb40f359f2777fdd9a8df4d30ce10531" alt="Screenshot from 2025-02-19 16-53-39"
This is not correct because ACHILES@SPECTERDEV.ONMICROSOFT.COM is a member of a role assignable group (ALL SPECTERDEV USERS@SPECTEROPS DEVELOPMENT)
data:image/s3,"s3://crabby-images/5bb73/5bb73cd5c34c296a78f186b0be42b95a41455645" alt="image"
Since it's a member of a role assignable group, only Global Administrator Role, Privileged Authentication Administrator Role, or Partner Tier2 Support Role can perform a reset password operation.
You can quickly disable my change by commenting out these lines I added in TenantRoleAssignments()
data:image/s3,"s3://crabby-images/005fd/005fdf1984a3c7c3474bc18f615e556de1b02acd" alt="image"
Types of changes
Checklist: