Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingMedium
A security auditor is reviewing the access control strategy for an Azure subscription. They need to ensure that users only have the minimum necessary permissions to perform their job functions, and these permissions are granted directly to their user accounts or groups. Which Azure identity and access management concept does this describe?
- ARole-Based Access Control (RBAC)
- BShared Access Signatures (SAS)
- CManaged Identities
- DConditional Access
Show answer & explanationAnswer & explanation
Correct answer: A. Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) in Azure allows you to manage who has access to Azure resources, what they can do with those resources, and what areas they have access to. It aligns with the principle of least privilege by assigning specific roles with defined permissions.
Why the other options are wrong
- B. Shared Access Signatures (SAS) provide delegated access to Azure Storage resources, not general Azure resource access management for users.
- C. Managed Identities provide an Azure AD identity for Azure services without managing credentials, not for user access control.
- D. Conditional Access is a feature of Azure AD that evaluates conditions for access, but RBAC is the underlying system for defining what permissions a user has once conditions are met.
Role-Based Access Control (RBAC)
An authorization system in Azure that allows you to manage access to Azure resources by assigning roles to users, groups, and applications.
- Aligns with the principle of least privilege.
- Defines what actions identities can perform on resources.
- Permissions are inherited through the resource hierarchy.
Memory trick: RBAC is the 'role assignment' that 'unlocks' specific 'actions'.