An Entra principal has been granted the Azure Resource Manager role called “Owner” over an Azure Resource Manager asset.
AZOwner targets resources in Azure Resource Manager (for example AZResourceGroup, AZSubscription, and AZVM) through role assignment called “Owner”.
The edges AZOwner and AZOwns are distinct as they each apply their own distinct identity and access management platform (AzureRM and Entra ID respectively) with distinct mechanics, abuse primitives, and remediation steps.
Everything a Contributor can do, with the addition of assigning rights to resources. Object ownership means almost all abuses are possible against the target object.