Soru

Zorluk: OrtaAzure RBAC and Subscription Governance

An enterprise is designing a subscription governance and access management strategy for a new business unit's development workloads. The environment consists of multiple subscriptions grouped under a single Management Group. You need to delegate administrative access to a team of developers so they can manage Azure Virtual Machines and Azure App Services within these subscriptions. The solution must minimize administrative overhead when developers join or leave the team, prevent developers from permanently holding privileged roles, and adhere to the principle of least privilege. Which two actions should you include in the design? (Select two.)

  1. Configure eligible assignments for the Virtual Machine Contributor and Website Contributor roles to a Microsoft Entra ID security group at the Management Group scope using Microsoft Entra Privileged Identity Management (PIM).Cevap
  2. Add the developers to a Microsoft Entra ID security group and assign the roles to the group rather than to individual user accounts.Cevap
  3. C
    Assign the Contributor role directly to the individual developer user accounts at the Management Group scope.
  4. D
    Configure permanently active Owner role assignments for the developer user accounts at the Subscription scope.

Cevap

To meet the requirements, you should configure eligible assignments for the Virtual Machine Contributor and Website Contributor roles to a Microsoft Entra ID security group at the Management Group scope using Microsoft Entra Privileged Identity Management (PIM), and add the developers to the Microsoft Entra ID security group rather than assigning roles directly to individual user accounts.
The correct design uses a Microsoft Entra ID security group to minimize administrative overhead, and assigns the specific Virtual Machine Contributor and Website Contributor roles at the Management Group scope as eligible assignments using Microsoft Entra PIM. This setup ensures inheritance across all subscriptions, keeps roles scoped to only what is needed (least privilege), and enforces just-in-time (JIT) access activation so developers do not hold permissions permanently.

Adım Adım Çözüm

1
Identify the required roles based on least privilege.
Virtual Machine Contributor and Website Contributor roles are selected instead of broad Contributor or Owner roles.
This limits developers' permissions to only managing Virtual Machines and App Services, satisfying the principle of least privilege.
2
Determine the identity assignment method to minimize administrative overhead.
A Microsoft Entra ID security group is created, and developers are added to this group.
Assigning permissions to a group simplifies management because membership changes are handled dynamically in Microsoft Entra ID rather than updating individual role assignments.
3
Establish just-in-time access and scope boundary.
Configure eligible assignments for the selected roles to the security group at the Management Group scope using Microsoft Entra PIM.
This ensures developers do not permanently hold privileged access (complying with PIM eligibility) and the permissions inherit down to all subscriptions within the Management Group.

Anahtar Kavram

Implementing scalable subscription governance using Microsoft Entra ID groups, Microsoft Entra PIM for just-in-time access, and least-privilege RBAC role assignments at the Management Group scope.
Tahmini Süre:2m 0s
Bu soruyu puanla