Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceHard

A security auditor needs read-only access to all resources within a specific Azure subscription to review configurations, but must not be able to modify or deploy any resources. The auditor also needs to view all Azure AD user and group properties. Which two built-in roles, when combined, would grant the minimum necessary permissions?

  1. ASecurity Reader and Global Reader
  2. BMonitoring Reader and Authentication Administrator
  3. CReader and Directory Readers
  4. DContributor and User Administrator
Show answer & explanation

Correct answer: C. Reader and Directory Readers

The 'Reader' role provides read-only access to all resources in an Azure subscription. The 'Directory Readers' role provides read-only access to Azure AD users and groups. Combining these two roles satisfies the requirement for read-only access to both Azure resources and Azure AD objects, adhering to the principle of least privilege.

Why the other options are wrong

  • A. Security Reader is limited to security-related configurations. Global Reader provides read-only access to all Azure AD, but Reader is needed for Azure resources.
  • B. Monitoring Reader is specific to monitoring data. Authentication Administrator grants write access for authentication settings.
  • D. Contributor grants write access, violating the read-only requirement. User Administrator grants write access to users.

Azure RBAC Reader + Azure AD Directory Readers

The combination of the Azure Role-Based Access Control (RBAC) 'Reader' role and the Azure Active Directory (Azure AD) 'Directory Readers' role. This provides comprehensive read-only access across Azure resources and Azure AD objects.

  • Reader role for Azure resources (VMs, networks, storage)
  • Directory Readers role for Azure AD users, groups, applications
  • Adheres to the principle of least privilege for auditing

Memory trick: To read everything, you need a Reader for Azure and a Directory Reader for AD.

More Manage Azure identities and governance questions