LEARNING AZURE / YOUR CLOUD LEARNING SPACE
No account neededAbout
Identity / 35–45 min

Apply least-privilege access

Learn to answer a practical operations question: who can do what, and where? Inspect Azure role assignments before making a carefully scoped access change.

What you’ll be able to do

  • Distinguish authentication from authorization.
  • Identify principal, role, and scope in a role assignment.
  • Explain why resource-group access is narrower than subscription access.
Before you beginComplete lesson 1. You need permission to read role assignments. The optional assignment requires role-assignment write permissions and an approved test user; Contributor alone does not grant those permissions.

Get the idea

Identity is not permission

Microsoft Entra ID establishes identity. Azure RBAC grants permission to operate Azure resources. A successful sign-in does not by itself allow someone to change a virtual machine.

The three parts of an assignment

A principal is a user, group, service principal, or managed identity. A role describes permitted actions. Scope determines where those actions apply. Assignments at a parent scope can be inherited by child resources.

Work from the smallest scope

A teammate who only needs to inspect a lab usually does not need subscription-wide rights. Reader access to the learning resource group is a narrower starting point. Directory roles and Azure resource roles serve different purposes.

Try it yourself

  1. Open rg-learningazure in the Azure portal and select Access control (IAM).
  2. Inspect Role assignments. Compare assignments at this scope with inherited assignments. Record the principal, role, and scope for one example without sharing personal details.
  3. Use Check access for your own account. Explain how your effective permissions differ from your sign-in identity.
  4. Optional: with approval and role-assignment write permissions, add Reader for an existing test user at this resource group only. Do not use a production administrator account as the test user.
  5. Ask the test user to inspect the group and verify they cannot create or modify a resource through this assignment. Other inherited permissions may still grant writes; inspect those before interpreting the result.
Check your resultYou can explain one effective permission in terms of principal, role, scope, and inheritance.

Finish the lab

Remove only the test Reader assignment you created. Do not remove inherited or pre-existing assignments. Never grant yourself broader permissions merely to finish the exercise.

Quick knowledge check

Does Reader on a resource group necessarily allow reading the contents of every blob in that group?

Reveal the explanation

No. Management-plane visibility differs from data-plane access. Blob content access generally requires an appropriate data role or another authorized access method.

Take this with you

Grant the permissions a task requires at the narrowest practical scope.

Go deeper

AI-assisted lesson · Reference links checked October 3, 2026. Exercises are teaching examples; they have not been executed against your Azure subscription.