Knowledgebase

Azure Identity and Access for Resources Print

  • microsofttechnology, microsoft, domainrenewal, ssl, database, security, woocommerce, permissions
  • 0

Controlling who can do what.

WHAT ROLE-BASED ACCESS CONTROL PROVIDES

Permissions assigned at a scope: management group, subscription, resource group or resource.

WHAT THE PRINCIPLE IS

The narrowest role, at the narrowest scope, for the shortest time.

WHAT TO ASSIGN TO

Groups, not individuals.

WHAT COMMON ROLES EXIST

Reader, contributor, and owner, plus service-specific roles.

WHAT OWNER ADDS BEYOND CONTRIBUTOR

The ability to grant access to others.

WHY THAT MATTERS

It is effectively full control.

WHAT MANAGED IDENTITIES PROVIDE

An identity for a resource, so it can authenticate to other services without stored credentials.

WHY THAT MATTERS ENORMOUSLY

It removes secrets from configuration entirely.

WHAT TO USE THEM FOR

Applications reaching databases, storage and key vaults.

WHAT A KEY VAULT PROVIDES

Secure storage for secrets, keys and certificates, with access controlled and audited.

WHAT TO PUT THERE

Anything that would otherwise sit in configuration.

WHAT TO CONFIGURE

Rotation, and alerting on expiry.

WHAT TO REVIEW

Role assignments, periodically, especially at subscription scope.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot