Different from entra roles
- Roles consist of actions that are assigned to security principal at a certain scope
- Scope can be at subscription or resource groups
- Ideally apply it to a group / can be applied to individual user also but that is cumbersome
- Leverage pim for just in time
Types of Roles
- Built-in
- Owner - full access to manage resources and assign roles
- contributor - access to manage resources
- reader - can see, not make any changes
- etc.
- custom roles
references:
Azure roles, Microsoft Entra roles, and classic subscription administrator roles Azure Built in roles reference
Subscribe to NordLetter
A weekly newsletter on living in Finland.