Controlling who can do what.
WHAT ROLE-BASED ACCESS CONTROL PROVIDES
Permissions assigned at a scope: management group, subscription, resource group or resource.
WHAT THE PRINCIPLE IS
The narrowest role, at the narrowest scope, for the shortest time.
WHAT TO ASSIGN TO
Groups, not individuals.
WHAT COMMON ROLES EXIST
Reader, contributor, and owner, plus service-specific roles.
WHAT OWNER ADDS BEYOND CONTRIBUTOR
The ability to grant access to others.
WHY THAT MATTERS
It is effectively full control.
WHAT MANAGED IDENTITIES PROVIDE
An identity for a resource, so it can authenticate to other services without stored credentials.
WHY THAT MATTERS ENORMOUSLY
It removes secrets from configuration entirely.
WHAT TO USE THEM FOR
Applications reaching databases, storage and key vaults.
WHAT A KEY VAULT PROVIDES
Secure storage for secrets, keys and certificates, with access controlled and audited.
WHAT TO PUT THERE
Anything that would otherwise sit in configuration.
WHAT TO CONFIGURE
Rotation, and alerting on expiry.
WHAT TO REVIEW
Role assignments, periodically, especially at subscription scope.