Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityEasy
A developer is designing a system where an Azure Function App needs to publish messages to an Azure Service Bus topic. The Function App should have minimal necessary permissions. Which built-in Azure role should be assigned to the Function App's managed identity for this purpose?
- AService Bus Data Owner
- BService Bus Data Receiver
- CContributor
- DService Bus Data Sender
Show answer & explanationAnswer & explanation
Correct answer: D. Service Bus Data Sender
The 'Service Bus Data Sender' role provides permissions to send messages to Azure Service Bus entities. This aligns with the requirement for the Function App to 'publish messages' (send), while adhering to the principle of least privilege by not granting unnecessary owner or receiver permissions.
Why the other options are wrong
- A. Service Bus Data Owner grants full control, which violates the principle of least privilege.
- B. Service Bus Data Receiver only allows receiving messages, not sending them.
- C. Contributor grants broad management permissions across many Azure services and violates the principle of least privilege for data operations.
Azure Service Bus Data Roles
Built-in Azure roles that provide data plane access to Azure Service Bus entities, allowing for fine-grained control over sending and receiving messages.
- Service Bus Data Sender: Send messages
- Service Bus Data Receiver: Receive messages
- Service Bus Data Owner: Full control over data operations
Memory trick: Sender: You send; Receiver: You get.