Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium
A developer is creating an Azure Function App that needs to send sensitive notifications to an Azure Service Bus topic. The security team has mandated that the Function App should only have the minimum necessary permissions to publish messages to the topic and nothing more. Which Azure RBAC role should be assigned to the Azure Function App's managed identity to meet this requirement?
- AContributor
- BAzure Service Bus Data Receiver
- CAzure Service Bus Data Owner
- DAzure Service Bus Data Sender
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Service Bus Data Sender
The 'Azure Service Bus Data Sender' role grants permissions to send messages to Service Bus queues and topics. This aligns perfectly with the principle of least privilege, as the Function App only needs to publish (send) messages, not own, receive, or manage the Service Bus.
Why the other options are wrong
- A. The 'Contributor' role grants broad management access to all resources in a resource group, far exceeding the necessary permissions for sending messages to Service Bus.
- B. The 'Data Receiver' role is for consuming messages, not sending them.
- C. The 'Data Owner' role grants full control, including managing the Service Bus. This violates the principle of least privilege.
Service Bus Data Roles
Azure RBAC roles specific to Azure Service Bus for controlling data plane operations like sending and receiving messages.
- Data Owner: Full control (send, receive, manage).
- Data Sender: Send messages only.
- Data Receiver: Receive/consume messages only.
- Essential for implementing least privilege access to Service Bus.
Memory trick: To send, the Function needs the 'Sender' role for Service Bus.