Part of azure governance
Role based access control / giving something permissions at a certain scope when needed
- Applies to all items in control plane (management groups,resource groups, resources)
- can apply to some storage roles in data plane
- Inherited
License
free to use
Limits
- 4000 per subscription
- 500 per management group
- 5000 per tenant for custom roles
202404061316 Azure Roles 202401072038 Azure RBAC custom roles
references:
Paths into this note
6 notes lead here
-
So in RBAC what azure roles apply to which plane - control or data
-
Azure RBAC and encryption
-
RBAC may not be granular enough or we start to hit Azure RBAC#Limits