Entra ID Roles

Overview

  1. Permissions applied for Entra ID
  2. Always think least privilege

Security Principal

  • Who or what is being assigned access?
  • Entra user
  • entra group (requires p1) /
    • needs to be setup as such at creation time (Entra ID roles can be assigned to the group)
    • isAssignableToRole property
    • immutable so only at setup
  • app

Role Definition

Built-in Entra roles

  1. Global Administrator
  2. User Administrator
  3. Billing Administrator

Scope

  1. Where will the permissions apply?
  2. Hierarchy
  3. Traditionally used to be global
  4. Can be:
    1. tenant
    2. Entra Administrative Units
    3. Entra resource
      1. Microsoft Entra groups
      2. Enterprise applications
      3. Application registrations
  5. If role is assigned on container level role is applied to items contained in it
  6. If role is applied at resource level it applies to the resource
    1. In particular does not extend to members of the groups

references

Entra RBAC Use groups to manage Entra roles Builtin Roles

Subscribe to NordLetter

A weekly newsletter on living in Finland.

UPDATED