Your company has an Azure subscription containing a resource group named Dev-RG. You need to grant a junior administrator the ability to create and manage all resources within Dev-RG. The junior administrator must not be allowed to assign roles or grant permissions to other users. Which of the following should you assign to the junior administrator's account for Dev-RG?
- AThe Owner role
- The Contributor roleCevap
- CAn Azure Policy definition
- DThe Reader role
Cevap
The Contributor role
The Contributor role allows the user to manage all resources within the specified scope, including creating and deleting resources, but it does not allow the user to assign roles in Azure RBAC or grant permissions to others. This perfectly aligns with the security requirements of the scenario.
Adım Adım Çözüm
Anahtar Kavram
Azure Role-Based Access Control (RBAC) built-in roles and scope
Tahmini Süre:1m 0s