Soru

Zorluk: OrtaAzure Role Assignments and Scopes

The Azure resource hierarchy for a retail company consists of the following components:
* Management Group: `MG-Corporate`
* Subscription: `Sub-Production`
* Resource Group: `RG-Web-Apps`

An IT administrator named Admin1 is assigned only the Global Administrator role in the Microsoft Entra ID tenant.
Admin1 must delegate permissions to a development team by assigning the Contributor role at the `RG-Web-Apps` scope. However, Admin1 is currently unable to view `Sub-Production` or `RG-Web-Apps` in the Azure portal.
Which action should Admin1 perform to ensure they can assign the role?

  1. A
    Create a Microsoft Entra Administrative Unit, add `RG-Web-Apps` to the unit, and assign the User Access Administrator role to Admin1.
  2. B
    Assign the Owner role to Admin1 at the root management group and create a custom Deny assignment at `Sub-Production` to restrict access to other resource groups.
  3. Elevate access in the properties of the Microsoft Entra directory to manage Azure resources.Cevap
  4. D
    Assign the Owner role to Admin1 at the subscription scope using Microsoft Entra ID roles.

Cevap

Elevate access in the properties of the Microsoft Entra directory to manage Azure resources.
Elevating access in the properties of the Microsoft Entra directory temporarily grants the Global Administrator the User Access Administrator role at the root scope (//). Since permissions inherit down the Azure resource hierarchy, the administrator will receive the User Access Administrator role for all management groups, subscriptions, and resource groups associated with the directory, allowing them to assign roles at the resource group scope.

Adım Adım Çözüm

1
Identify the separation of planes between Microsoft Entra ID (directory roles) and Azure RBAC (resource roles).
Confirm that being a Global Administrator does not automatically grant access to subscriptions or resource groups.
By default, Microsoft Entra ID roles do not inherit permissions into Azure resource management.
2
Elevate access in the Microsoft Entra directory properties.
Admin1 is assigned the User Access Administrator role at the root scope (//).
This toggle enables directory Global Administrators to manage access to all subscriptions and management groups associated with the tenant.
3
Utilize inherited permissions to manage role assignments.
The User Access Administrator role inherits down to the resource group level (`RG-Web-Apps`), granting Admin1 the necessary permission to assign the Contributor role.
Azure RBAC assignments are inherited from higher scopes to lower scopes.

Anahtar Kavram

Azure RBAC inheritance and directory-level access elevation
Tahmini Süre:1m 15s
Bu soruyu puanla