1. Identify the operation before requesting access
A fictional support team is receiving a funds application. The person managing directory users now needs to inspect virtual-machine configuration. The Microsoft Entra role used in the directory does not automatically grant that Azure resource access. Record the intended operation, identity, and scope. For configuration inspection, assess Reader at the required scope; for other actions, identify suitable permissions. Also distinguish service configuration from data stored in that service. A clearly defined access request supports review of the need without distributing Owner for convenience. The project should explain who approves access and how support demonstrates that it can perform the authorized task.
2. Interpret roles and authentication
An identity can sign in yet lack permission to modify a resource. Authentication and authorization answer different questions. MFA adds protection to identity verification; registering it does not assign roles. Contributor allows resource management at the applicable scope but cannot assign Azure RBAC roles. If support needs to grant another person access, involve an identity specifically authorized for that task. Conditional Access can apply controls according to access signals such as identity, device, or location. None of these concepts justifies removing the other controls. At the handover meeting, use a simple matrix of job, operation, and scope to make responsibilities understandable.
3. Give the application an identity
A batch process needs to query a service supporting Microsoft Entra authentication. A managed identity obtains tokens without the team managing an application password. The identity must still be authorized at the target. In this exercise, token acquisition succeeds and authorization is missing; distributing an administrative key would bypass the design without fixing the missing assignment. The application must use the intended identity and the service must support the mechanism. This example supplements identity foundations without requiring detailed SDK configuration for AZ-900. For operational transition, document the identity, dependency, and person authorized to review access when the batch requirement changes.
4. Distinguish prevention and correction
The project receives a rule restricting resource locations. An Azure Policy with Deny can prevent covered creation or update requests that violate the rule. When evaluating existing resources, it marks noncompliant ones; that alone does not migrate or delete them. The team needs an inventory, owner, and plan for the earlier situation. A remediation window may require coordination with business, operations, and architecture. Functional approval of a delivery does not change the policy’s technical effect. In this lesson, assume the assignment applies and enforcement is enabled; exemptions, scope, and parameters must be examined when assessing a real configuration.
5. Separate locks and tag classification
CanNotDelete protects against covered management deletions while retaining authorized modifications. ReadOnly adds update restrictions and can interfere with operations a team considers routine. Always confirm the request type and plane involved; a management lock is not a universal guarantee about all data. A tag such as centre=FUNDS classifies resources. Applying it to a group does not automatically copy it onto resources in that group. To classify resources, apply tags or configure a suitable mechanism. Do not confuse actual resource tags with inheritance or grouping capabilities in cost reports. During delivery, inspect a resource sample and identify who maintains classification.
6. Prepare governance for a hybrid environment
Not every application server moves in the same phase. Azure Arc can bring supported external resources into Azure management and governance capabilities while retaining their location. A resource group or connectivity alone does not configure that integration. In the meeting, distinguish inventory, connection, management, and hosting. The project manager should identify what stays on premises, who maintains relevant agents or extensions, and how the agreed integration is validated. The exercise aims to recognize Arc’s purpose without presenting an executed installation. Complete the handover with defined support operations, approved access, and evidence suited to the requirement instead of depending solely on the selected service name.
An operator with Contributor changes application configuration but cannot grant Reader to a colleague. The next action is to involve the owner authorized to manage access at the required scope.
Common pitfalls
Confusing MFA with permission, Contributor with access management, Deny with automatic migration, or group tags with actual resource tags.
Related topics: Microsoft Entra and RBAC · Policy, locks, and tags · Hybrid operations with Azure Arc
Identify the operation and apply the corresponding control: authentication, authorization, permitted configuration, management protection, and classification have distinct responsibilities.
Reference: Azure roles and Microsoft Entra roles · AZ-900 skills measured July 20, 2026