Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceHard

A security auditor needs read-only access to review all resources, configurations, and logs across a specific Azure subscription. The auditor should not be able to make any changes. Additionally, the auditor needs to view user and group properties within Azure Active Directory. Which combination of built-in Azure roles should be assigned?

  1. ASecurity Reader role on the subscription and Authentication Administrator role in Azure AD.
  2. BContributor role on the subscription and User Administrator role in Azure AD.
  3. COwner role on the subscription and Global Reader role in Azure AD.
  4. DReader role on the subscription and Directory Readers role in Azure AD.
Show answer & explanation

Correct answer: D. Reader role on the subscription and Directory Readers role in Azure AD.

The 'Reader' role provides read-only access to all resources within an Azure subscription. The 'Directory Readers' role in Azure AD grants read-only access to users and groups in Azure AD. This combination meets both requirements without granting excessive permissions.

Why the other options are wrong

  • A. Security Reader covers security-specific read access, but not all resource types. Authentication Administrator grants write permissions for authentication methods.
  • B. Contributor allows modifying resources, violating 'read-only'. User Administrator allows managing users, which is write access.
  • C. Owner provides full access, including write and delete, which violates the 'read-only' requirement. Global Reader is too broad for just users/groups.

Azure RBAC Reader + Azure AD Directory Readers

A combination of roles providing read-only access to Azure resources (Reader) and read-only access to Azure AD users and groups (Directory Readers).

  • Reader role for Azure resources (subscriptions, resource groups, resources).
  • Directory Readers role for Azure Active Directory objects (users, groups).
  • Ensures least privilege for auditing purposes across both Azure and Azure AD.

Memory trick: Auditor needs to read everywhere, but never write a single thing.

More Manage Azure identities and governance questions