Azure has two separate role systems, and exam questions often test whether you know which one applies. Microsoft Entra roles control what someone can do in the directory itself: create users, reset passwords, manage groups, register applications and configure tenant settings. Examples are Global Administrator, User Administrator, Groups Administrator, Helpdesk Administrator, License Administrator and Application Administrator. Their scope is the whole tenant or an administrative unit (a container that limits a role to a subset of users or groups), and you assign them in Microsoft Entra ID > Roles and administrators. Azure role-based access control (RBAC) roles control what someone can do to Azure resources: virtual machines, storage accounts, networks. Their scopes are management groups, subscriptions, resource groups and resources, and you assign them on a resource's Access control (IAM) blade. The two systems are independent. A Global Administrator does not automatically have any access to subscriptions, and a subscription Owner cannot create users in Entra ID unless they also hold a suitable Entra role. When you read a question, first decide whether the task touches directory objects (users, groups, apps, licenses, passwords) or Azure resources; that decides which role system the answer comes from.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.