Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium
A security administrator needs to grant a new auditor read-only access to all resources and their configurations within a specific Azure subscription. The auditor also needs to view Azure Active Directory (Azure AD) user and group properties for auditing purposes. Which combination of Azure built-in roles should be assigned?
- AOwner role at the subscription scope and Security Reader role in Azure AD
- BReader role at the subscription scope and Directory Readers role in Azure AD
- CContributor role at the subscription scope and Global Reader role in Azure AD
- DSecurity Reader role at the subscription scope and User Administrator role in Azure AD
Show answer & explanationAnswer & explanation
Correct answer: B. Reader role at the subscription scope and Directory Readers role in Azure AD
The 'Reader' role at the subscription scope provides read-only access to all Azure resources within that subscription. The 'Directory Readers' role in Azure AD grants read access to all user and group properties in Azure AD, which is necessary for auditing directory objects. This combination fulfills both requirements with the least privilege.
Why the other options are wrong
- A. Owner provides full access, including management of access, which is excessive for an auditor; Security Reader in Azure AD has limited scope for directory objects.
- C. Contributor and Global Reader grant excessive permissions (write access to resources, read all admin roles in AD) beyond what's required for an auditor.
- D. Security Reader in Azure RBAC focuses on security-related resources; User Administrator in Azure AD grants write permissions, which is too much.
Azure RBAC Reader + Azure AD Directory Readers
This combination of roles provides comprehensive read-only access: the Azure RBAC Reader role for Azure resources and the Azure AD Directory Readers role for Azure Active Directory objects.
- Reader (Azure RBAC) allows viewing all Azure resources.
- Directory Readers (Azure AD) allows viewing user and group properties in Azure AD.
- Adheres to the principle of least privilege for auditing.
Memory trick: To 'Read Everything', you need both 'Resource Reader' and 'Directory Reader'.