Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsHard

A healthcare organization is migrating its patient records system to Azure. The system requires fine-grained authorization, where access to individual patient records is determined by the user's role (e.g., Doctor, Nurse, Administrator) and their association with a specific patient or department. The application is built on Azure App Service and uses Azure SQL Database. How should this authorization be implemented?

  1. AImplement application-level authorization logic within the patient records system.
  2. BUtilize Azure AD security groups to control access to individual patient records.
  3. CUse Azure Role-Based Access Control (RBAC) to assign roles to users for the Azure SQL Database.
  4. DConfigure network security groups (NSGs) to restrict access to the Azure SQL Database.
Show answer & explanation

Correct answer: A. Implement application-level authorization logic within the patient records system.

Fine-grained authorization at the individual record level, based on application-specific roles and data relationships (like patient-doctor association), is best handled by application-level authorization logic. Azure RBAC operates at the resource level (e.g., database, table), not individual data rows or records within the database.

Why the other options are wrong

  • B. Azure AD security groups can be used to assign users to roles, but the logic to translate these roles into fine-grained data access (e.g., 'patient X's records') still needs to be in the application.
  • C. Azure RBAC controls access to Azure resources (like the database itself or specific tables), not individual rows or records within the database based on application logic.
  • D. NSGs control network traffic and connectivity, not user authorization to data within a database.

Application-level Authorization

Application-level authorization refers to the process where an application's code enforces access control rules based on business logic, user roles, and data relationships, typically at a fine-grained level (e.g., individual records or fields).

  • Enables fine-grained control over data access within an application.
  • Leverages application-specific roles and business rules.
  • Often implemented in conjunction with identity providers for user authentication and higher-level role assignment.

Memory trick: For patient records, the application is the 'Doctor's Order' for what can be seen.

More Design identity, governance, and monitoring solutions questions