Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planMedium
A company is required to implement a 'least privilege' security model for their Azure environment. They want to ensure that developers only have permissions to deploy resources within specific resource groups for their projects, and only to specific resource types (e.g., Web Apps, Azure SQL Database). They should NOT be able to create Virtual Networks or modify subscription-level settings. Which Azure service is best suited to define and enforce these granular permissions?
- AAzure Policy
- BAzure Role-Based Access Control (RBAC)
- CAzure Active Directory (Azure AD)
- DAzure Security Center (now Defender for Cloud)
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Role-Based Access Control (RBAC)
Azure Role-Based Access Control (RBAC) allows you to manage who has access to Azure resources, what they can do with those resources, and what areas they have access to. It enables defining granular permissions at the subscription, resource group, or individual resource level, making it ideal for enforcing least privilege by limiting developers to specific actions on specific resource types within designated scopes.
Why the other options are wrong
- A. Azure Policy enforces organizational standards and assesses compliance, but it defines *what* configurations are allowed, not *who* can perform actions on resources. RBAC grants the 'who'.
- C. Azure AD manages identities and authentication, but RBAC is the mechanism for authorization (what resources they can access and what they can do).
- D. Azure Security Center (Defender for Cloud) provides security posture management and threat protection, not a mechanism for defining granular access control.
Azure Role-Based Access Control (RBAC)
A system for managing authorization in Azure that allows you to specify who has access to Azure resources, what actions they can perform, and what resources or scopes they have access to.
- Enforces the principle of least privilege.
- Grants access at management group, subscription, resource group, or resource scope.
- Uses roles (built-in or custom) to define permissions.
Memory trick: RBAC 'Grants Specific Keys' to 'Specific Doors'.