Skip to content

Issue: Eligible Members/Owners of Groups (PIM for Groups) Not Enumerated #106

@zh54321

Description

@zh54321

First of all, thank you for this fantastic tool. It has been incredibly useful, especially in enumerating CAPs and eligible role assignments as a low-privileged user, which has significantly helped in many assessments.

However, I noticed a potential issue:
Eligible members/owners of groups (PIM for groups) are not being enumerated.

For example:

  1. While I can see that the group has the Global Administrator role assigned:
    1

  2. I'm unable to see the eligible members and owners of the group:
    group_members

  3. However, in the portal, it is visible that the group has eligible owners/members:
    2

Therefore, assignments to groups which have privileged roles could be missed.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions