A non-admin role that can grant itself administrator
What it is
Human user holds a role that can rewrite the security model.
Why it matters
A non-admin whose custom role grants role or user administration can grant themselves anything through the API: a low-privilege login that can bootstrap itself to full control.
Find it yourself
Same method as the integration version, pointed at roles held by human users. Read the privilege list of every custom role for role and user administration. Built-in administrative roles are expected to hold these; a custom business role holding them is the finding.
How to fix it
Remove those privileges, reserve admin for named people, and turn on prevent-elevation-of-privilege.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.