IDENTITY SECURITY · LAB
Delegate role administration and watch the delegation limit hold
Give Ben limited role administration, then see the tenant allow what he holds and refuse an over-broad role, a Tenant Admin assignment and actions after his role is removed.
ReadyUses your lab tenant
The lesson
Builds on: Attacks on recovery and the help desk.
New to the labs? Start with the lab toolkit and the shared cast and names every lab uses.
Partly ready. Most of this lab runs today. Steps that wait on platform features are marked, and Missing infrastructure says what they need.
- G22 End-user authorization engine (PDP, RBAC/ABAC/ReBAC for application data)
- G45 Management role assignments scoped to part of a tenant or assigned to groups
Your progress
Press Start before you begin. Only events your tenant records after that count, in the order below. Checking reads your tenant's Audit, so you need Audit read access in it.
Sign in to start this lab and check your progress. Log in or create an account.
Ben creates a role from permissions he holds
Recorded as
tenant.roles.createsucceeded.Remove the lock permission from Ben's role
Recorded as
tenant.roles.updatesucceeded.Ben's role with a permission he no longer holds is refused
Recorded as
tenant.roles.createrejected.Ben cannot assign Tenant Admin to Cora
Recorded as
tenant.users.management_roles.assignrejected.Remove Ben's role administration
Recorded as
tenant.users.management_roles.assignsucceeded.Ben's next role change is refused
Recorded as
tenant.roles.deleterejected.
Setup
In Roles, create
lab-role-adminwith these permissions: list roles, create roles, update roles, delete roles, list users, lock users, and assign management roles to users (tenant.roles.read,tenant.roles.create,tenant.roles.update,tenant.roles.delete,tenant.users.read,tenant.users.lock,tenant.users.management_roles.assign).In Users, give Ben
lab-role-adminalongsidelab-support.Press Start on this page.
Walkthrough
In a private window, sign in as Ben and open
$ISSUER/manage, then Roles. Create a role namedlab-tmp-viewerwith only the permission to list users. It is saved. Note that every permission Ben does not hold is greyed out in the editor.
Why it matters: this is the lesson's delegation limit. Ben can grant only what he holds himself, so role administration cannot become a way to hand out user deletion or policy changes.
As Ben, start creating another role,
lab-tmp-locker, and tick the permission to lock users, which Ben holds. Do not save yet. In your own window, as Tenant Admin, editlab-role-adminand remove the lock permission. Now save Ben's role. The tenant refuses it.
Why it matters: the editor showed the box when the page loaded, but the server checks what Ben holds when the request arrives. The lesson's "the service that performs an action has to check the permission itself" is exactly this.
As Ben, open Users, choose Cora, and try to give her the Tenant Admin role. The tenant refuses it.
Why it matters: assigning a role is granting its permissions. Ben does not hold Tenant Admin's permissions, so he cannot give them to anyone, including an account he controls.
As Ben, look at the built-in Tenant Admin role in Roles. It is protected and cannot be edited by anyone.
Why it matters: the lesson's self-edit route works when editing a role a person holds silently grows their own access. A protected recovery role cannot be edited, and the tenant checks every role edit against what the editor holds.
As Tenant Admin, remove
lab-role-adminfrom Ben in Users. As Ben, without refreshing, try to deletelab-tmp-viewer. The tenant refuses it.
Why it matters: the tenant evaluates Ben's current assignments on every request. A role removed at 10:00 stops working at 10:00, not when Ben's session ends.
In Audit, source User directory, search for Ben's user ID as the actor. Read the refusals in order: the over-broad role, the Tenant Admin assignment, and the delete after removal, each with reason
access_denied.
Why it matters: refused attempts belong in the records alongside the successes. An ordinary account trying to give itself more is rarely an accident, and the actor field shows who asked.
Break it
As Tenant Admin, try to delete
lab-supportwhile Ben still holds it. The tenant refuses it because the role is in use, so a removal that changes who holds power is checked against current assignments. Nothing was removed, so there is nothing to restore.
Check your work
Check my progress confirms Ben's role creation, the role edit, the refused role, the refused Tenant Admin assignment, the removal of Ben's role and the refusal afterwards.
In Audit, source User directory, the refusals show reason
access_deniedand the refused deletion of an assigned role showsrole_in_use.
Cleanup
As Tenant Admin, delete
lab-tmp-viewer(andlab-tmp-lockerif it was ever saved).Delete
lab-role-adminonce nobody holds it. Keeplab-supportassigned to Ben.
Missing infrastructure
G45: management roles cannot be assigned to groups or scoped to part of a tenant, so the lesson's nested-group path to user administration has no counterpart. Once it exists, the lab will give a group a role and confirm that only someone who could grant the role directly may change the group's members.
G22: there is no authorization engine for application data, so horizontal escalation (reading a colleague's photos by changing an identifier) cannot be practiced against a real API. Once it exists, the lab will request Cora's album as Ava and see the decision refused and recorded.