azure_enumerate_role_definitions
Enumerate Azure RBAC role definitions to find custom roles with dangerous wildcard permissions, privilege escalation risks, and overly broad assignments.
Instructions
Enumerate Azure RBAC role definitions including custom roles. Identifies dangerous wildcard permissions (Actions: ['*']), overly broad custom roles, and privilege escalation paths via PassRole/roleAssignments-write. Checks all role definitions scoped to the subscription.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| subscriptionId | Yes | Azure subscription ID | |
| includeBuiltIn | No | Include built-in role definitions in output. Default: false (custom roles only) | |
| format | No | Output format: 'markdown' (default) or 'json' |