Understand the concept
Authentication verifies identity; authorization determines what that identity may do. Entra ID supports identities and mechanisms such as MFA and Conditional Access. Azure RBAC assigns actions to identities at a scope. A broad-scope role can grant access to descendant resources, so scope matters as much as the role name.
Apply and decide
Azure Policy evaluates or enforces resource rules under the configured effect. RBAC answers “who can act”; Policy helps with “what configuration is allowed.” Locks can protect against certain management operations but replace neither backups nor every data-plane control. An audit effect identifies noncompliance; it is not automatically deny.
Workplace application
An operator receives Reader on a group but retains a broad assignment inherited from the subscription. The new role does not automatically eliminate previous access. Analyze all applicable assignments before concluding exposure was reduced. Also distinguish Policy audit, which flags noncompliance, from suitable preventive configuration. A lock limits management operations within its scope and does not create a data-recovery copy.
To prevent new deployments outside approved locations, evaluate a policy with the appropriate effect. To let an operator only read resources, evaluate RBAC at the necessary scope.
Common pitfalls
Assuming Reader removes inherited Owner or audit prevents requests.
Related topics: Costs, monitoring, and deployment · Cloud models and responsibilities
Identity, configuration rules, and management protection are complementary controls.
Reference: Azure role-based access control overview · AZ-900 skills measured July 20, 2026