Concept and mechanism
A token identifies a subject to a resource but does not itself grant every operation. Start by identifying who performs the action, on which plane and scope, and with which inherited assignments. Managed identity reduces credential management without removing role requirements. Delegated permissions involve a user; autonomous processes can require application permissions and appropriate consent. PIM allows activating eligible access during a window with configured controls. Eligibility and activation are different states. Before enforcing Conditional Access, evaluate impact through report-only and interpret results as evaluation rather than an already enforced block. Retain operational recovery access defined by the process.
Guided application
In a fictional batch that loses Key Vault access after moving to RBAC, compare identity and data roles against previous permissions. Management Contributor does not equal secret reading. NotActions subtracts actions from one role, while another role can grant them; it is not a global deny. deployIfNotExists or modify remediation uses its own identity with required permissions. Reevaluating compliance does not automatically fix missing authorization. ARM locks protect management operations rather than every service data operation. For backups, Resource Guard should represent actual separation of duties. At handover, record scope, owners, access evidence, and recovery before removing temporary privileges.
403 after vault migration: first establish identity, networking, and data roles; avoid making everyone an administrator.
Common pitfalls
Eligibility as active access; Reader as secret reading; NotActions as deny; lock as complete data protection.
Related topics: Storage, SQL, and keys · Private networks and diagnosis · Agent and AI security
Establish effective permission for the identity performing each operation.
Reference: Role Actions DataActions and NotActions · SC-500 guide updated 2026-05-13; Microsoft security documentation accessed 2026-09-30