Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsMedium

A company requires a solution to manage access to its Azure resources using role-based access control (RBAC). They have a complex organizational structure and need to assign permissions at various granularities, from subscription level down to individual resources. The solution must also support custom roles and integrate with Azure AD groups. Which authorization framework should be used?

  1. AAzure AD Security Groups
  2. BAzure Policy
  3. CAzure Resource Locks
  4. DAzure Role-Based Access Control (RBAC)
Show answer & explanation

Correct answer: D. Azure Role-Based Access Control (RBAC)

Azure Role-Based Access Control (RBAC) is the authorization system used to manage access to Azure resources. It allows you to assign specific permissions to users, groups, and applications at different scopes (management group, subscription, resource group, or individual resource), supports built-in and custom roles, and integrates with Azure AD groups.

Why the other options are wrong

  • A. Azure AD Security Groups are used to group users for easier RBAC assignment, but they are not the RBAC framework itself.
  • B. Azure Policy enforces organizational standards and compliance, but it does not define who has access to perform actions on resources.
  • C. Azure Resource Locks prevent accidental deletion or modification of resources, not defining who can access what.

Azure Role-Based Access Control (RBAC)

An authorization system built on Azure Resource Manager that provides fine-grained access management of Azure resources. It allows you to control who has access to which resources, what they can do with those resources, and at what scope.

  • Uses 'who', 'what', 'where' model (Security principal, Role definition, Scope)
  • Supports built-in and custom roles
  • Integrates with Azure AD users, groups, and service principals

Memory trick: RBAC: ROLES grant access, like job titles.

More Design identity, governance, and monitoring solutions questions