Soru

Zorluk: OrtaAzure Role-Based Access Control (RBAC)

A user assigned the Contributor role for an Azure resource group can create new resources within that resource group and delegate access to those resources by assigning built-in roles to other users.

Cevap: Cevap

Cevap

False
The correct answer is False because the Contributor role does not grant permission to assign roles or delegate access, which is restricted to the Owner and User Access Administrator roles.

Adım Adım Çözüm

1
Analyze the permissions associated with the Contributor role in Azure Role-Based Access Control (RBAC).
The Contributor role grants full permissions to create and manage all types of Azure resources within the assigned scope.
To determine what resources and resource management actions the role can execute.
2
Check if the Contributor role includes authorization permissions, specifically role assignments.
The Contributor role explicitly excludes the ability to write or delete role assignments (Microsoft.Authorization/roleAssignments/*).
To verify if a Contributor has the capability to delegate access to other users.
3
Identify which roles are required for delegating access.
Only roles with user access administration privileges, such as Owner or User Access Administrator, can assign roles to other users.
To conclude that the statement is false because delegation requires a higher privilege level than Contributor.

Anahtar Kavram

Azure RBAC Contributor vs. Owner permissions
Bu soruyu puanla