Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium
A company is implementing a new Azure subscription for a development team. The team lead needs to be able to create, modify, and delete all resources within a specific resource group, but should NOT be able to modify access permissions (RBAC) for that resource group. Which built-in Azure RBAC role is most appropriate for the team lead?
- AOwner
- BUser Access Administrator
- CContributor
- DReader
Show answer & explanationAnswer & explanation
Correct answer: C. Contributor
The Contributor role allows full management of all resources within a resource group, including creating, modifying, and deleting them. However, it explicitly excludes the ability to manage access permissions (RBAC), which aligns with the requirement.
Why the other options are wrong
- A. The Owner role grants full access, including the ability to manage access permissions, which is explicitly disallowed for the team lead.
- B. The User Access Administrator role is specifically for managing user access to Azure resources and does not grant permissions to manage the resources themselves.
- D. The Reader role only allows viewing resources and does not permit creation, modification, or deletion.
Azure RBAC Contributor Role
A built-in Azure role that grants full management access to all resources except the ability to manage access to Azure resources (RBAC).
- Can create, manage, and delete resources.
- Does not grant permissions to manage role assignments.
- Commonly used for developers and resource managers.
Memory trick: Contributor can build and destroy the box, but can't control who holds the keys.