Security & Threat Intelligence · 25.07.2026, 15:29 UTC
Keeping a Short Leash: New AzureHound Least-Privilege Documentation
| Schweregrad | info |
|---|---|
| Kategorie | Security & Threat Intelligence |
| Quelle | SpecterOps ↗ |
| Veröffentlicht | 25.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
TL;DR: AzureHound now has documented least-privilege permissions. This post walks through the research behind those permissions. We recommend least privilege for tighter access control, while recognizing broader read rights can reduce maintenance across future releases.
Introduction
At SpecterOps, the Research team’s role is to ensure we stay ahead in adversary simulation and identity attack path management (APM). We organize that work around three pillars;
Adversary Tradecraft, turning real attacker behavior into something defenders can recognize; like Valdemar Carøe’s post Catching Credential Guard Off Guard sharing next-gen credential dumping techniques that bypass modern protections
Graph Expansion, where we extend the BloodHound graph into new identity surfaces; like Michael Grafnetter’s work on the Okta Platform in his recent post Discovering Unexpected Okta Attack Paths with BloodHound
Product Features, improving BloodHound by researching and prototyping new capabilities, and refining existing ones
That final pillar is where this post lands; I was tasked with bringing the official AzureHound permission requirements to least-privilege. That work produced three concrete deliverables that are live today: a new reference article, AzureHound Data Collection and Permissions, plus updated manual and scripted deployment steps that ship with the narrower permission set by default.
This post walks through my research to give you a glimpse behind the scenes of the problem definition, research methodology, and the decisions to reach a solution.
Problem …