Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsHard

A healthcare organization is deploying a new patient management system to Azure. The system requires strict access control, ensuring that only authorized personnel can view patient records. Specifically, doctors can view all records, nurses can view records for their assigned patients, and administrative staff can only view demographic information. The solution must be granular and prevent 'over-permissioning'. Which Azure authorization mechanism should be used?

  1. AApplication-level Authorization
  2. BAzure Active Directory (Azure AD) Groups
  3. CAzure Role-Based Access Control (RBAC)
  4. DAzure Policy
Show answer & explanation

Correct answer: A. Application-level Authorization

While Azure RBAC can define broad roles (Owner, Contributor, Reader) at the resource level, it cannot typically implement granular, data-level authorization such as 'nurses can view records for their assigned patients' or 'administrative staff can only view demographic information'. This requires application-level authorization logic, where the application itself validates the user's role and specific data permissions before displaying information.

Why the other options are wrong

  • B. Azure AD Groups are for organizing users, not for defining granular data-level access rules.
  • C. Azure RBAC operates at the control plane (resource management) level, not usually at the data plane (individual record access) with such fine granularity.
  • D. Azure Policy enforces organizational standards and compliance, not granular data access within an application.

Application-level Authorization

Application-level authorization refers to access control logic implemented within an application itself, which determines what specific data or functions a user can access based on their identity, roles, or attributes.

  • Provides fine-grained data access control.
  • Implemented by the application's business logic.
  • Supplements, rather than replaces, platform-level authorization (like RBAC).

Memory trick: Application: The bouncer deciding what data you can touch.

More Design identity, governance, and monitoring solutions questions