Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceEasy
A company is implementing a new Azure subscription for a project. They need to ensure that no resources within this subscription can be accidentally deleted or modified by any user, including subscription owners, for a critical production environment. Which Azure feature should be configured to prevent such accidental actions?
- AAzure Management Groups
- BAzure AD Conditional Access
- CAzure Policy with a 'Deny' effect
- DAzure Resource Locks
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Resource Locks
Azure Resource Locks are specifically designed to prevent accidental deletion or modification of resources, even by users with owner permissions. They operate at a level above RBAC, ensuring that critical resources are protected.
Why the other options are wrong
- A. Azure Management Groups help organize subscriptions but do not prevent accidental deletion or modification of resources within those subscriptions.
- B. Azure AD Conditional Access controls access to Azure AD and applications based on conditions, not direct prevention of resource modification or deletion within a subscription.
- C. Azure Policy with a 'Deny' effect can prevent certain actions, but it's more about enforcing standards and can be circumvented by a determined owner if not carefully crafted. Resource Locks are more absolute for accidental protection.
Azure Resource Locks
Azure Resource Locks prevent accidental deletion or modification of critical Azure resources, even by users with administrative permissions, ensuring resource stability.
- Can be applied at subscription, resource group, or individual resource scope.
- Two types: CanNotDelete and ReadOnly.
- Must be explicitly removed before resource can be deleted or modified.
Memory trick: Resource Locks are like a 'do not touch' sign that even owners must respect.