Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium
A global software company maintains a complex Azure environment with numerous subscriptions, resource groups, and resources. They need to ensure that administrative access to specific resources, such as production SQL Databases and virtual networks, is restricted to only authorized personnel and that permissions are applied at the lowest possible scope to prevent excessive privileges. Which principle and corresponding Azure feature should be primarily used to enforce this security requirement?
- APrinciple of least privilege with Azure AD PIM
- BPrinciple of shared responsibility with Azure Security Center
- CPrinciple of defense in depth with Azure Firewall
- DPrinciple of least privilege with Azure RBAC
Show answer & explanationAnswer & explanation
Correct answer: D. Principle of least privilege with Azure RBAC
The 'principle of least privilege' dictates that users should only have the minimum necessary permissions to perform their job functions. Azure Role-Based Access Control (RBAC) is the Azure feature that directly enables the implementation of this principle by allowing granular permission assignments at various scopes (management group, subscription, resource group, or individual resource).
Why the other options are wrong
- A. PIM manages privileged access duration, but RBAC is the underlying mechanism for assigning the actual least privilege permissions.
- B. Shared responsibility outlines security responsibilities, and Security Center provides posture management, neither directly assigns least privilege permissions.
- C. Defense in depth is a strategy, and Azure Firewall provides network security; neither directly manages identity permissions.
Azure Role-Based Access Control (RBAC)
An authorization system built on Azure Resource Manager that provides fine-grained access management of Azure resources.
- Allows assignment of roles to users, groups, service principals, or managed identities.
- Permissions can be granted at management group, subscription, resource group, or resource scope.
- Enforces the principle of least privilege by defining specific actions allowed.
Memory trick: RBAC and Least Privilege: Only the right keys for the right locks.