Your organization's Azure environment is structured with the following resource hierarchy:
- Tenant Root Group (Management Group)
- Security-MG (Management Group)
- Subscription1 (Subscription)
- RG-Secure (Resource Group)
You need to grant a security auditor named Auditor1 the ability to view all resources and access control assignments within RG-Secure. Auditor1 must not be able to modify any resources or manage access control assignments.
Which role should you assign to Auditor1 to meet the requirement under the principle of least privilege?
- Reader assigned at the RG-Secure scopeAnswer
- BGlobal Reader assigned in Microsoft Entra ID
- CReader assigned at the Subscription1 scope, with a Deny assignment at the RG-Secure scope
- DStorage Blob Data Reader assigned at the RG-Secure scope
Answer
Reader assigned at the RG-Secure scope
The Reader role at the RG-Secure scope allows the auditor to view all resources and access control configurations in that specific resource group without modifying them or inheriting broader permissions from higher scopes, adhering to the principle of least privilege.
Step-by-Step Solution
Key Concept
Azure RBAC Built-in Roles and Scopes
Estimated Time:1m 0s