Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceHard

A company has an Azure subscription and wants to delegate the ability to create new resource groups to a specific group of users, but these users should not be able to manage any resources within those resource groups or delete existing resource groups. Which custom role definition should be created to meet these requirements?

  1. AMicrosoft.Resources/subscriptions/resourceGroups/read
  2. BMicrosoft.Resources/subscriptions/resourceGroups/delete
  3. CMicrosoft.Resources/subscriptions/resourceGroups/join/action
  4. DMicrosoft.Resources/subscriptions/resourceGroups/write
Show answer & explanation

Correct answer: D. Microsoft.Resources/subscriptions/resourceGroups/write

To create new resource groups, the 'write' permission on resource groups at the subscription scope is required. This allows creation and update but does not grant permissions to manage resources inside or delete resource groups, aligning with the requirements.

Why the other options are wrong

  • A. Microsoft.Resources/subscriptions/resourceGroups/read only allows viewing resource groups, not creating them.
  • B. Microsoft.Resources/subscriptions/resourceGroups/delete grants permission to delete resource groups, which is explicitly disallowed.
  • C. Microsoft.Resources/subscriptions/resourceGroups/join/action is not a standard, relevant permission for creating resource groups in this context.

Azure RBAC Custom Role Definition (Resource Group Creation)

Creating a custom Azure RBAC role to grant specific, granular permissions, such as the ability to create new resource groups without broader management rights.

  • Custom roles allow fine-grained control.
  • Permissions are defined using 'actions' and 'notActions'.
  • The 'write' action on resource groups enables creation/update.

Memory trick: To 'write' a new chapter, you need the 'write' permission.

More Manage Azure identities and governance questions