Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A company is implementing a new Azure subscription for a development team. The team lead needs to be able to create, modify, and delete all resources within a specific resource group, but should NOT be able to modify access permissions (RBAC) for that resource group. Which built-in Azure RBAC role is most appropriate for the team lead?

  1. AOwner
  2. BUser Access Administrator
  3. CContributor
  4. DReader
Show answer & explanation

Correct answer: C. Contributor

The Contributor role allows full management of all resources within a resource group, including creating, modifying, and deleting them. However, it explicitly excludes the ability to manage access permissions (RBAC), which aligns with the requirement.

Why the other options are wrong

  • A. The Owner role grants full access, including the ability to manage access permissions, which is explicitly disallowed for the team lead.
  • B. The User Access Administrator role is specifically for managing user access to Azure resources and does not grant permissions to manage the resources themselves.
  • D. The Reader role only allows viewing resources and does not permit creation, modification, or deletion.

Azure RBAC Contributor Role

A built-in Azure role that grants full management access to all resources except the ability to manage access to Azure resources (RBAC).

  • Can create, manage, and delete resources.
  • Does not grant permissions to manage role assignments.
  • Commonly used for developers and resource managers.

Memory trick: Contributor can build and destroy the box, but can't control who holds the keys.

More Manage Azure identities and governance questions