Azure Privilege Escalation Via Service Principal

In this blog, we will look at a variation of a real-world attack path to escalate our privileges from a compromised Application Administrator account in Azure to Global admin through a service principal. Before diving into the attack’s details, let us understand some Azure basics to help us further down the path. What is Azure?...