← SC-500: cloud and AI security
01 / 6 · 40 MIN

Identity, access, and governance

Distinguish authentication, authorization, and security-change execution.

Concept and mechanism

A token identifies a subject to a resource but does not itself grant every operation. Start by identifying who performs the action, on which plane and scope, and with which inherited assignments. Managed identity reduces credential management without removing role requirements. Delegated permissions involve a user; autonomous processes can require application permissions and appropriate consent. PIM allows activating eligible access during a window with configured controls. Eligibility and activation are different states. Before enforcing Conditional Access, evaluate impact through report-only and interpret results as evaluation rather than an already enforced block. Retain operational recovery access defined by the process.

Guided application

In a fictional batch that loses Key Vault access after moving to RBAC, compare identity and data roles against previous permissions. Management Contributor does not equal secret reading. NotActions subtracts actions from one role, while another role can grant them; it is not a global deny. deployIfNotExists or modify remediation uses its own identity with required permissions. Reevaluating compliance does not automatically fix missing authorization. ARM locks protect management operations rather than every service data operation. For backups, Resource Guard should represent actual separation of duties. At handover, record scope, owners, access evidence, and recovery before removing temporary privileges.

IN PRACTICE

403 after vault migration: first establish identity, networking, and data roles; avoid making everyone an administrator.

Common pitfalls

Eligibility as active access; Reader as secret reading; NotActions as deny; lock as complete data protection.

Related topics: Storage, SQL, and keys · Private networks and diagnosis · Agent and AI security

Take this idea with you

Establish effective permission for the identity performing each operation.

Create account

Reference: Role Actions DataActions and NotActions · SC-500 guide updated 2026-05-13; Microsoft security documentation accessed 2026-09-30