Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceHard
A security administrator needs to grant a new auditor read-only access to all resources and their configurations across multiple Azure subscriptions within a specific Management Group. The auditor should not be able to view user sign-in logs or audit logs within Azure Active Directory. Which role assignment strategy should the administrator use?
- AAssign the 'Reader' role at the Management Group scope.
- BAssign a custom role with 'Microsoft.Resources/subscriptions/read' and 'Microsoft.Authorization/roleAssignments/read' at the Management Group scope.
- CAssign the 'Security Reader' role at the Management Group scope.
- DAssign the 'Global Reader' role at the Management Group scope.
Show answer & explanationAnswer & explanation
Correct answer: C. Assign the 'Security Reader' role at the Management Group scope.
The 'Security Reader' role provides read-only access to security-related configurations and resources, including Azure resources and their settings. Crucially, unlike 'Global Reader' or a simple 'Reader' role, 'Security Reader' does not grant access to Azure AD user sign-in logs or audit logs, aligning with the requirement to restrict viewing of these specific logs.
Why the other options are wrong
- A. The 'Reader' role at the Management Group scope grants read access to Azure resources but does not inherently exclude Azure AD sign-in/audit logs if they are considered part of security-related data that 'Reader' might indirectly access in some contexts.
- B. A custom role would be complex to create and maintain to precisely exclude specific log types while granting broad resource read access; the 'Security Reader' role already fits this nuanced requirement.
- D. The 'Global Reader' role is an Azure AD role that grants read access to *everything* in Azure AD, including sign-in logs and audit logs, which directly contradicts the requirement to *exclude* these logs.
Azure RBAC: Security Reader Role
The Azure 'Security Reader' role provides read-only access to security-related information and settings across Azure resources, but it specifically excludes access to user sign-in logs and audit logs within Azure AD.
- A built-in Azure RBAC role.
- Grants read access to security center, policy, resource configurations.
- Does NOT grant access to Azure AD sign-in logs or audit logs.
- Suitable for security auditors who need to review security posture without user activity details.
Memory trick: The Security Reader sees the walls, but not the guest book.