Azure separates two kinds of operations. The control plane (management plane) manages resources themselves: creating a Key Vault, changing a Service Bus tier, deleting a Cosmos DB account. It goes through Azure Resource Manager. The data plane works with the data inside: reading a secret, sending a message, pulling an image, querying items. Roles such as Owner and Contributor are control-plane roles; they let you manage the resource but, for services using RBAC data access, they do not by themselves let you read the data. Apps need data-plane roles, assigned to their managed identity with least privilege.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.