What you’ll be able to do
- Distinguish authentication from authorization.
- Identify principal, role, and scope in a role assignment.
- Explain why resource-group access is narrower than subscription access.
Get the idea
Identity is not permission
Microsoft Entra ID establishes identity. Azure RBAC grants permission to operate Azure resources. A successful sign-in does not by itself allow someone to change a virtual machine.
The three parts of an assignment
A principal is a user, group, service principal, or managed identity. A role describes permitted actions. Scope determines where those actions apply. Assignments at a parent scope can be inherited by child resources.
Work from the smallest scope
A teammate who only needs to inspect a lab usually does not need subscription-wide rights. Reader access to the learning resource group is a narrower starting point. Directory roles and Azure resource roles serve different purposes.
Try it yourself
- Open rg-learningazure in the Azure portal and select Access control (IAM).
- Inspect Role assignments. Compare assignments at this scope with inherited assignments. Record the principal, role, and scope for one example without sharing personal details.
- Use Check access for your own account. Explain how your effective permissions differ from your sign-in identity.
- Optional: with approval and role-assignment write permissions, add Reader for an existing test user at this resource group only. Do not use a production administrator account as the test user.
- Ask the test user to inspect the group and verify they cannot create or modify a resource through this assignment. Other inherited permissions may still grant writes; inspect those before interpreting the result.
Finish the lab
Remove only the test Reader assignment you created. Do not remove inherited or pre-existing assignments. Never grant yourself broader permissions merely to finish the exercise.
Quick knowledge check
Does Reader on a resource group necessarily allow reading the contents of every blob in that group?
Reveal the explanation
No. Management-plane visibility differs from data-plane access. Blob content access generally requires an appropriate data role or another authorized access method.
Take this with you
Grant the permissions a task requires at the narrowest practical scope.
Go deeper
AI-assisted lesson · Reference links checked October 3, 2026. Exercises are teaching examples; they have not been executed against your Azure subscription.