Azure custom role permits role-definition changes

Restrict role-definition changes to administrators who need them.

Description

Microsoft.Authorization/roleDefinitions/write permits creating or changing custom roles. It is separate from role-assignment permission, but changing an already assigned role can affect users’ effective permissions.

Potential impact

An erroneous or malicious role-definition change can expand access for accounts using that role.

Remediation

Remove this action and broad wildcards that include it from accounts that do not manage roles. Allow only role-definition read access when inspection is sufficient.

Examples

These excerpts reduce role-definition write permission to read permission.

Before

hcl
resource "azurerm_role_definition" "example" {
  role_definition_id = "00000000-0000-0000-0000-000000000000"
  name               = "my-custom-role-definition"
  scope              = data.azurerm_subscription.primary.id

  permissions {
    actions     = ["Microsoft.Authorization/roleDefinitions/write"]
    not_actions = []
  }
}

After

hcl
resource "azurerm_role_definition" "example" {
  role_definition_id = "00000000-0000-0000-0000-000000000000"
  name               = "my-custom-role-definition"
  scope              = data.azurerm_subscription.primary.id

  permissions {
    actions     = ["Microsoft.Authorization/roleDefinitions/read"]
    not_actions = []
  }
}

References