Azure Roles

Different from entra roles

  1. Roles consist of actions that are assigned to security principal at a certain scope
  2. Scope can be at subscription or resource groups
  3. Ideally apply it to a group / can be applied to individual user also but that is cumbersome
  4. Leverage pim for just in time

Types of Roles

  1. Built-in
    1. Owner - full access to manage resources and assign roles
    2. contributor - access to manage resources
    3. reader - can see, not make any changes
    4. etc.
  2. custom roles

references:

Azure roles, Microsoft Entra roles, and classic subscription administrator roles Azure Built in roles reference

Subscribe to NordLetter

A weekly newsletter on living in Finland.

UPDATED