Microsoft Certified: Azure AI Engineer AssociatePlan and manage an Azure AI solutionEasy
A data science team is developing an Azure AI solution that uses Azure Machine Learning workspaces. They need to control access to various resources within the workspace, such as experiments, models, and datasets, based on user roles. Which Azure security mechanism should you recommend for managing these permissions?
- AAzure Role-Based Access Control (RBAC).
- BAzure Policy.
- CNetwork Security Groups (NSGs).
- DAzure Active Directory (AAD) security groups.
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Role-Based Access Control (RBAC).
Azure Role-Based Access Control (RBAC) allows you to manage who has access to Azure resources, what they can do with those resources, and what areas they can access. It is the primary mechanism for granular permission management within Azure resources like Machine Learning workspaces.
Why the other options are wrong
- B. Azure Policy helps enforce organizational standards and assess compliance at scale, but it doesn't directly manage who can perform actions on resources; RBAC does that.
- C. NSGs filter network traffic to and from Azure resources in a VNet. They are for network security, not resource-level access control.
- D. AAD security groups are used to group users for easier management, but RBAC roles are what define the actual permissions applied to those groups or individual users.
Azure Role-Based Access Control (RBAC)
An authorization system built on Azure Resource Manager that provides fine-grained access management of Azure resources. It allows you to manage who has access to Azure resources, what they can do with those resources, and what areas they can access.
- Manages permissions at various scopes (subscription, resource group, resource).
- Assigns roles to users, groups, or service principals.
- Supports built-in and custom roles.
Memory trick: RBAC is the 'bouncer' for your Azure resources, checking everyone's role.