Microsoft Certified: Azure Security Engineer AssociateManage identity and accessHard

A client is configuring Azure AD for a new enterprise application. This application requires a service principal to interact with Azure resources on its behalf. The security team insists that the service principal should have the minimum necessary permissions and that these permissions should be reviewed regularly. Which method ensures the principle of least privilege and supports regular access reviews for the service principal's permissions?

  1. AAssigning a custom RBAC role with specific permissions to the service principal at the resource group level.
  2. BUsing Azure AD Privileged Identity Management (PIM) for the service principal's role assignments.
  3. CGranting directory roles (e.g., Global Administrator) to the service principal.
  4. DAssigning the 'Owner' role directly to the service principal at the subscription level.
Show answer & explanation

Correct answer: A. Assigning a custom RBAC role with specific permissions to the service principal at the resource group level.

Assigning a custom RBAC role with only the required permissions at the resource group level ensures the principle of least privilege. While PIM can manage access reviews for eligible roles, a custom role at the narrowest scope is the primary method for least privilege for a fixed service principal.

Why the other options are wrong

  • B. PIM is typically used for human administrators to activate eligible roles on a just-in-time basis. While PIM can do access reviews, assigning a custom role at the correct scope is the foundational least privilege step for a service principal, which usually requires persistent access.
  • C. Granting directory roles like 'Global Administrator' to a service principal is a severe security risk and violates least privilege.
  • D. Assigning 'Owner' at the subscription level violates the principle of least privilege due to excessive permissions and scope.

Service Principal Least Privilege

Configuring an application's service principal with only the permissions absolutely necessary to perform its functions at the smallest possible scope.

  • Use built-in roles if they fit, otherwise create custom roles.
  • Assign roles at the lowest possible scope (resource, resource group, subscription, management group).
  • Regularly review assigned permissions for continued necessity.

Memory trick: Give machines only the exact tools they need, in their own workspace.

More Manage identity and access questions