Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceHard

A security administrator needs to grant a new auditor read-only access to all resources and their configurations across multiple Azure subscriptions within a specific Management Group. The auditor should not be able to view user sign-in logs or audit logs within Azure Active Directory. Which role assignment strategy should the administrator use?

  1. AAssign the 'Reader' role at the Management Group scope.
  2. BAssign a custom role with 'Microsoft.Resources/subscriptions/read' and 'Microsoft.Authorization/roleAssignments/read' at the Management Group scope.
  3. CAssign the 'Security Reader' role at the Management Group scope.
  4. DAssign the 'Global Reader' role at the Management Group scope.
Show answer & explanation

Correct answer: C. Assign the 'Security Reader' role at the Management Group scope.

The 'Security Reader' role provides read-only access to security-related configurations and resources, including Azure resources and their settings. Crucially, unlike 'Global Reader' or a simple 'Reader' role, 'Security Reader' does not grant access to Azure AD user sign-in logs or audit logs, aligning with the requirement to restrict viewing of these specific logs.

Why the other options are wrong

  • A. The 'Reader' role at the Management Group scope grants read access to Azure resources but does not inherently exclude Azure AD sign-in/audit logs if they are considered part of security-related data that 'Reader' might indirectly access in some contexts.
  • B. A custom role would be complex to create and maintain to precisely exclude specific log types while granting broad resource read access; the 'Security Reader' role already fits this nuanced requirement.
  • D. The 'Global Reader' role is an Azure AD role that grants read access to *everything* in Azure AD, including sign-in logs and audit logs, which directly contradicts the requirement to *exclude* these logs.

Azure RBAC: Security Reader Role

The Azure 'Security Reader' role provides read-only access to security-related information and settings across Azure resources, but it specifically excludes access to user sign-in logs and audit logs within Azure AD.

  • A built-in Azure RBAC role.
  • Grants read access to security center, policy, resource configurations.
  • Does NOT grant access to Azure AD sign-in logs or audit logs.
  • Suitable for security auditors who need to review security posture without user activity details.

Memory trick: The Security Reader sees the walls, but not the guest book.

More Manage Azure identities and governance questions