Azure ABAC

Part of azure governance
Attribute based access control

Why?

  1. RBAC may not be granular enough or we start to hit [[202404061249 Azure RBAC#Limits]]
  2. Adds conditions to roles assignments based on attributes of resources and principal accessing

Where

Currently restricted to roles that have blob storage or queue storage data actions.

How to assign conditions

  1. On user level, we could create and add custom attributes for users in “Entra ID”
  2. In the role (in-built or custom) you can add a condition

references:

ABAC overview

Subscribe to NordLetter

A weekly newsletter on living in Finland.

UPDATED