A company has an Azure subscription and uses Azure Active Directory (Azure AD). An administrator needs to create a new custom role definition for a security auditor. This role should allow the auditor to view all security-related settings and logs across all resource groups within the subscription, but explicitly prevent them from making any changes. The auditor should also be able to review Azure AD sign-in and audit logs. Which built-in role should be used as a starting point for the custom role, and which additional permissions are needed for Azure AD logs?
- AReader; Security Reader for Azure AD logs
- BContributor; Global Reader for Azure AD logs
- CSecurity Reader; Reports Reader for Azure AD logs
- DMonitoring Reader; Directory Readers for Azure AD logs
Show answer & explanationAnswer & explanation
Correct answer: C. Security Reader; Reports Reader for Azure AD logs
The 'Security Reader' built-in role provides read-only access to security-related settings and logs within Azure resources. To access Azure AD sign-in and audit logs, the 'Reports Reader' role is needed, as it grants permissions to read all reports data in Azure AD, including audit and sign-in logs. Combining these two roles (or using Security Reader as a base and adding Reports Reader permissions) fulfills all requirements.
Why the other options are wrong
- A. Reader provides general read access but not specifically security-focused read access. Security Reader is a better fit for the Azure resources. 'Security Reader for Azure AD logs' is not a standard Azure AD role.
- B. Contributor has write access, which violates the 'prevent any changes' requirement. Global Reader is too broad for just logs and might grant more permissions than needed.
- D. Monitoring Reader provides read access to monitoring data, but 'Security Reader' is more comprehensive for security settings. Directory Readers is a broader role than necessary for just logs, giving read access to directory information.
Custom Role for Security Auditor
A custom Azure RBAC role for security auditors typically combines read-only access to security settings and logs within Azure resources with specific read permissions for Azure AD audit and sign-in logs.
- Security Reader for Azure resource security settings/logs.
- Reports Reader for Azure AD sign-in/audit logs.
- Must be read-only (deny write actions).
Memory trick: Security Reader + Reports Reader = Total Audit Vision.