StudyToCert

All certifications / Azure Administrator / Lessons

Microsoft Certified: Azure Administrator Associate AZ-104 · Domain 1: Manage Azure identities and governance

Resource locks: CanNotDelete vs ReadOnly, inheritance and who can remove them

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Resource locks protect important resources from accidental changes, including by people who have full permissions. Role-based access control (RBAC) might let an Owner delete a production database, but a lock stops the delete until someone deliberately removes the lock first. Locks are a safety catch, not an access-control system: they do not decide who can act, they add a deliberate extra step before dangerous operations. That extra step is exactly what prevents a mistyped command or an over-eager cleanup script from destroying production. Locks also apply to automation, so pipelines and scripts running as service principals are stopped just like people.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Azure Administrator for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Azure Administrator study plan