A healthcare organization is migrating its patient records system to Azure. The system requires fine-grained authorization, where access to individual patient records is determined by the user's role (e.g., Doctor, Nurse, Administrator) and their association with a specific patient or department. The application is built on Azure App Service and uses Azure SQL Database. How should this authorization be implemented?
- AImplement application-level authorization logic within the patient records system.
- BUtilize Azure AD security groups to control access to individual patient records.
- CUse Azure Role-Based Access Control (RBAC) to assign roles to users for the Azure SQL Database.
- DConfigure network security groups (NSGs) to restrict access to the Azure SQL Database.
Show answer & explanationAnswer & explanation
Correct answer: A. Implement application-level authorization logic within the patient records system.
Fine-grained authorization at the individual record level, based on application-specific roles and data relationships (like patient-doctor association), is best handled by application-level authorization logic. Azure RBAC operates at the resource level (e.g., database, table), not individual data rows or records within the database.
Why the other options are wrong
- B. Azure AD security groups can be used to assign users to roles, but the logic to translate these roles into fine-grained data access (e.g., 'patient X's records') still needs to be in the application.
- C. Azure RBAC controls access to Azure resources (like the database itself or specific tables), not individual rows or records within the database based on application logic.
- D. NSGs control network traffic and connectivity, not user authorization to data within a database.
Application-level Authorization
Application-level authorization refers to the process where an application's code enforces access control rules based on business logic, user roles, and data relationships, typically at a fine-grained level (e.g., individual records or fields).
- Enables fine-grained control over data access within an application.
- Leverages application-specific roles and business rules.
- Often implemented in conjunction with identity providers for user authentication and higher-level role assignment.
Memory trick: For patient records, the application is the 'Doctor's Order' for what can be seen.