-
Book Overview & Buying
-
Table Of Contents
-
Feedback & Rating

Microsoft Identity and Access Administrator SC-300 Exam Guide
By :

Azure RBAC grants access through roles, which define a collection of permissions for specific Azure resources or scopes.
For example, the Contributor role grants broad permissions to create and manage objects within a resource group, while the Reader role provides read-only access. However, users can be assigned multiple roles, leading to a combined set of permissions. This combined group, known as effective permissions, governs what capabilities a user or other identity has inside its delegated scope.
Evaluating these permissions effectively ensures that users have the least privilege principle applied, which aids in minimizing security risks. Consider a scenario where a user is assigned both the Contributor and Reader roles at the resource group level. While the Contributor role grants broad permissions, the Reader role might override certain actions, resulting in a net effect of read-only access for the user. Understanding...