StudyToCert

All certifications / Azure Fundamentals / Lessons

Microsoft Certified: Azure Fundamentals AZ-900 · Domain 2: Describe Azure architecture and services

Azure role-based access control (RBAC), Zero Trust, defense in depth and Microsoft Defender for Cloud

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Authentication proves who someone is; authorization decides what they can do. Azure role-based access control (RBAC) is the authorization system for Azure resources. Instead of granting individual permissions to individual people, you create a role assignment made of three parts: a security principal (a user, group, service principal or managed identity), a role definition (a collection of allowed actions, such as reading or restarting VMs), and a scope (where the permissions apply). In the portal you open any resource, choose Access control (IAM), then Add role assignment; from the CLI you run az role assignment create --assignee alice@contoso.com --role Reader --resource-group rg-sales.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 8 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Azure Fundamentals for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Azure Fundamentals study plan