Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium
A company is setting up a new Azure subscription for a development team. The team lead needs to be able to create and manage all Azure resources within this subscription, including virtual machines, storage accounts, and networks. However, they should not be able to manage access permissions (RBAC) for other users. Which built-in Azure role should be assigned to the team lead at the subscription scope?
- AReader
- BContributor
- CUser Access Administrator
- DOwner
Show answer & explanationAnswer & explanation
Correct answer: B. Contributor
The Contributor role allows full management of all resources, but it does not allow managing access to resources. This perfectly matches the requirement for the team lead to manage resources without managing RBAC.
Why the other options are wrong
- A. Reader can only view Azure resources and cannot make any changes, which is insufficient for managing resources.
- C. User Access Administrator can only manage user access to Azure resources and nothing else, which is insufficient for managing resources.
- D. Owner has full access to manage all resources AND delegate access (manage RBAC), which is more than required.
Azure Contributor Role
A built-in Azure role that grants full access to manage all resources, but does not allow you to assign roles in Azure RBAC.
- Can create, update, delete resources.
- Cannot manage access permissions (RBAC).
- Often used for resource administrators.
Memory trick: Owner is King, Contributor is Craftsman, Reader is Observer.