Authentication proves who someone is; authorization decides what they can do. Azure role-based access control (RBAC) is the authorization system for Azure resources. Instead of granting individual permissions to individual people, you create a role assignment made of three parts: a security principal (a user, group, service principal or managed identity), a role definition (a collection of allowed actions, such as reading or restarting VMs), and a scope (where the permissions apply). In the portal you open any resource, choose Access control (IAM), then Add role assignment; from the CLI you run az role assignment create --assignee alice@contoso.com --role Reader --resource-group rg-sales.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 8 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.