-
Book Overview & Buying
-
Table Of Contents
-
Feedback & Rating

Microsoft Identity and Access Administrator SC-300 Exam Guide
By :

Built-in roles in Azure are predefined with specific permissions, offering a convenient way to grant common access levels. For example, the Virtual Machine Contributor built-in role allows users to manage most aspects of virtual machines, aligning with the permissions defined within the role.
Custom roles offer a more granular approach to managing access control compared to built-in roles. By tailoring permissions to specific job functions, organizations can implement the principle of least privilege effectively. Assigning custom roles involves specifying the security principal (user, group, service principal, or managed identity) to whom the role is assigned, the scope at which the role applies (subscription, management group, resource group, or individual resource), and the precise set of actions permitted within that scope.
When assigning roles, you’ll want to take the following into consideration: