NetSPI reports that 897 built-in roles and 22,018 permissions are available for Azure RBAC.
Public source
Publisher name
Public post
897 built-in roles. 22,018 permissions. That's Azure RBAC today, and it's only getting bigger. Most privilege escalation reviews start with roles: is this account Owner,…
Company
NetSPI
Human-Led AI-Accelerated Modern Pentesting
- Industry
- Computer and Network Security
- Location
- Minneapolis, US
- Company size
- 501–1,000 employees
About NetSPI
NetSPI® pioneered Penetration Testing as a Service (PTaaS) and leads the industry in modern, continuous pentesting. Combining world-class security professionals with AI and automation, NetSPI delivers clarity, speed, and scale across 50+ pentest types, attack surface management, and vulnerability prioritization. The NetSPI platform streamlines workflows and accelerates remediation, enabling our experts to focus on deep dive testing that uncovers vulnerabilities others miss. Trusted by the top 10 U.S. banks and Fortune 500 companies worldwide, NetSPI has been driving security innovation since 2001. NetSPI is headquartered in Minneapolis, MN, and available on AWS Marketplace.
See moreLatest activity
Latest activity from NetSPI
14 signals
Strategy & Corporate Development
NetSPI and Synack are merging to create a formidable offensive security platform.
Research & Knowledge
NetSPI reports that a built-in Azure role was fixed by 6/22 after being reported to MSRC on 6/8.
Products & Services
NetSPI reports that Thomas E. and Karl Fosaaen mapped individual permissions to escalation vectors using a role-first review approach, finding a built-in Azure role that could escalate to Owner through unconstrained role assignment.
Discover more
Similar signals
Similar public activity from other companies.
Products & Services
Inspect 365
Inspect 365 introduced a new feature called Conditional Access evaluation that resolves every policy against a single user, showing which policies apply, exclude them, and what they grant, with coverage conditional.
Products & Services
water IT Security & Defense
water IT Security & Defense updated the Entra Security Identity Responder, Security Operator, and Security Administrator roles to include four containment actions, with the Security Operator role limited to non-administrative accounts.
Products & Services
Blaze Information Security
Blaze Information Security provides resources on cloud and ISO 27001 pentesting.
Products & Services
Cybr
Cybr launched a standalone lab for discovering Azure Blob Storage misconfigurations using Prowler as part of the Learn Azure in 30 Days course.
Products & Services
SafeBreach