Microsoft Certified: Azure Security Engineer AssociateManage identity and accessHard
A company is implementing Role-Based Access Control (RBAC) in Azure to manage permissions for various teams. They need to assign permissions to a group of users to manage virtual machines within a specific resource group. The principle of least privilege must be applied. Which RBAC role assignment is the most appropriate for this scenario?
- AReader role at the resource group level
- BOwner role at the subscription level
- CVirtual Machine Contributor role at the subscription level
- DContributor role at the resource group level
Show answer & explanationAnswer & explanation
Correct answer: D. Contributor role at the resource group level
Assigning the 'Contributor' role at the 'resource group' level provides permissions to manage resources (including VMs) within that specific resource group, adhering to the principle of least privilege by scope and role, and avoiding the overly broad 'Owner' role.
Why the other options are wrong
- A. Reader role only allows viewing resources, not managing them.
- B. Owner at subscription level grants full control over all resources in the subscription, violating least privilege.
- C. Virtual Machine Contributor at subscription level gives VM management permissions across the entire subscription, which is broader than needed for a 'specific resource group'.
Azure RBAC Least Privilege
Assigning only the necessary permissions (role) at the narrowest possible scope to perform a task.
- Roles define what actions can be performed (e.g., Reader, Contributor, Owner).
- Scopes define where the permissions apply (e.g., management group, subscription, resource group, resource).
- Combining the right role with the right scope is crucial for security.
Memory trick: Give the right key to the right map, no more.