Azure Roles
Last updated:
AZURERBAC
Different from [[202401072001 Entra ID Roles|entra roles]]
- Roles consist of actions that are assigned to security principal at a certain scope
- Scope can be at [[202401101441 Azure subscriptions|subscription]] or [[202404051818 Resource Groups|resource groups]]
- Ideally apply it to a group / can be applied to individual user also but that is cumbersome
- Leverage [[202401121503 Entra Privileged Identity Management|pim]] for just in time
Types of Roles
- Built-in
- Owner - full access to manage resources and assign roles
- contributor - access to manage resources
- reader - can see, not make any changes
- etc.
- [[202401072038 Azure RBAC custom roles|custom roles]]
references:
Azure roles, Microsoft Entra roles, and classic subscription administrator roles Azure Built in roles reference