An attacker has gained access to an Azure VM and wants to escalate privileges by abusing the VM's managed identity. The managed identity has the 'Contributor' role on the subscription. Which of the following actions would allow the attacker to add a new user to an Azure AD group that has 'Global Administrator' role?
The 'Contributor' role on a subscription allows management of Azure resources but not Azure AD objects. Adding a user to an Azure AD group requires Azure AD permissions, which the managed identity lacks. Therefore, the attacker cannot perform this action with the given role.
Why this answer
Azure RBAC roles like 'Contributor' grant permissions to manage Azure resources, not Azure AD objects. Adding a user to an Azure AD group is an Azure AD operation that requires directory permissions. The managed identity does not have these permissions, so the attacker cannot escalate privileges this way.
The attacker would need to find a different path, such as compromising an account with Azure AD admin roles.
Exam trap
The trap here is conflating Azure RBAC roles with Azure AD roles, assuming that 'Contributor' allows modification of Azure AD groups, which it does not.