Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceHard

A company has an Azure subscription and uses Azure Active Directory (Azure AD). An administrator needs to create a new custom role definition for a security auditor. This role should allow the auditor to view all security-related settings and logs across all resource groups within the subscription, but explicitly prevent them from making any changes. The auditor should also be able to review Azure AD sign-in and audit logs. Which built-in role should be used as a starting point for the custom role, and which additional permissions are needed for Azure AD logs?

  1. AReader; Security Reader for Azure AD logs
  2. BContributor; Global Reader for Azure AD logs
  3. CSecurity Reader; Reports Reader for Azure AD logs
  4. DMonitoring Reader; Directory Readers for Azure AD logs
Show answer & explanation

Correct answer: C. Security Reader; Reports Reader for Azure AD logs

The 'Security Reader' built-in role provides read-only access to security-related settings and logs within Azure resources. To access Azure AD sign-in and audit logs, the 'Reports Reader' role is needed, as it grants permissions to read all reports data in Azure AD, including audit and sign-in logs. Combining these two roles (or using Security Reader as a base and adding Reports Reader permissions) fulfills all requirements.

Why the other options are wrong

  • A. Reader provides general read access but not specifically security-focused read access. Security Reader is a better fit for the Azure resources. 'Security Reader for Azure AD logs' is not a standard Azure AD role.
  • B. Contributor has write access, which violates the 'prevent any changes' requirement. Global Reader is too broad for just logs and might grant more permissions than needed.
  • D. Monitoring Reader provides read access to monitoring data, but 'Security Reader' is more comprehensive for security settings. Directory Readers is a broader role than necessary for just logs, giving read access to directory information.

Custom Role for Security Auditor

A custom Azure RBAC role for security auditors typically combines read-only access to security settings and logs within Azure resources with specific read permissions for Azure AD audit and sign-in logs.

  • Security Reader for Azure resource security settings/logs.
  • Reports Reader for Azure AD sign-in/audit logs.
  • Must be read-only (deny write actions).

Memory trick: Security Reader + Reports Reader = Total Audit Vision.

More Manage Azure identities and governance questions