Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium

A company is developing an Azure Function App that needs to send sensitive notifications to a queue in Azure Service Bus. The security team has mandated that the Function App should only have the minimum necessary permissions to send messages to this specific queue and no other operations (e.g., receiving, managing). Which Azure Service Bus data role should be assigned to the Function App's managed identity?

  1. AAzure Service Bus Data Owner
  2. BAzure Service Bus Data Sender
  3. CAzure Service Bus Data Receiver
  4. DAzure Service Bus Contributor
Show answer & explanation

Correct answer: B. Azure Service Bus Data Sender

The 'Azure Service Bus Data Sender' role is specifically designed to grant permissions to send messages to Service Bus queues or topics. This aligns with the principle of least privilege, ensuring the Function App can only perform the required 'send' operation and nothing more, as mandated by the security team.

Why the other options are wrong

  • A. The 'Azure Service Bus Data Owner' role grants full access to Service Bus data planes, including send, receive, and management operations, which violates the principle of least privilege.
  • C. The 'Azure Service Bus Data Receiver' role grants permission to receive messages from Service Bus queues or topics, which is not the required operation for sending notifications.
  • D. The 'Azure Service Bus Contributor' role grants full management access to Service Bus resources but does not include data plane access by default and is too broad for data operations.

Azure Service Bus Data Roles

Azure Role-Based Access Control (RBAC) roles specifically for granting data plane access to Azure Service Bus queues and topics.

  • Data Owner: Full data plane access (send, receive, Peek/Lock).
  • Data Sender: Send messages to queues/topics.
  • Data Receiver: Receive messages from queues/topics.

Memory trick: Sender sends, Receiver receives, Owner does all.

More Implement Azure security questions