BloodHoundAD / BloodHound

Six Degrees of Domain Admin
GNU General Public License v3.0
9.62k stars 1.7k forks source link

Incorrect "AZOwns" Edge for Azure Subscriptions #654

Open Freakazoidile opened 1 year ago

Freakazoidile commented 1 year ago

Description If a user is a "Owner" of a resource within a subscription (such as an application or VM) BloodHound indicates they have a "AZOwns" path for the entire subscription.

Expected behavior Only users who are a "Owner" role of the entire subscription should have the "AZOwns" path.

JonasBK commented 1 year ago

Hey @Freakazoidile,

Thanks for reporting this. We will look into it.