← AZ-104: Azure administration in production
01 / 7 · 23 MIN

Identities and effective access

Relate principal, role, and scope to the actual task.

Concept and mechanism

An Azure RBAC assignment combines a principal, a role definition, and a scope. The principal may represent a person, group, or application. Scope determines covered resources and inheritance to lower levels. Assignments are additive: Reader on a resource group does not reduce Contributor inherited from the subscription. To remove access, identify all relevant grants, including group membership. Distinguish Azure resource administration from Microsoft Entra directory administration. A resource role does not automatically grant user management, just as a directory role does not automatically represent access to every VM.

Guided application

For an access request, first list required operations and target resources. Use groups for stable responsibilities while retaining ownership and membership review. For workloads, managed identities avoid storing an application password, but still need destination authorization and code obtaining tokens through a supported mechanism. Choose identity lifecycle according to the workload and verify connectivity separately. After a change, test an allowed operation and an operation that should remain denied. Record the grant’s source to simplify future review and removal.

IN PRACTICE

An operator changes responsibilities. Adding Reader does not remove Contributor received through an old group; review that membership and access still needed.

Common pitfalls

Reviewing only direct assignments; confusing identity with authorization; broadening scope to solve an error without diagnosis.

Related topics: Governance, protection, and costs · Storage, delegation, and recovery

Take this idea with you

Effective access results from applicable grants, not merely the last assigned role.

Create account

Reference: Azure RBAC overview · AZ-104; skills measured 2026-04-17