Azure has two separate permission systems, and the exam expects you to know which one answers a given question. Microsoft Entra roles (formerly Azure AD roles) control the directory itself: users, groups, app registrations, licenses, Conditional Access and tenant settings. Azure role-based access control (Azure RBAC) controls Azure resources: subscriptions, virtual machines, storage accounts, key vaults and everything else managed through Azure Resource Manager (ARM). A Global Administrator can reset passwords for everyone but, by default, cannot delete a single VM. An Owner of a subscription can delete every VM in it but cannot create a user.
Common Entra built-in roles include Global Administrator, Privileged Role Administrator, User Administrator, Security Administrator, Security Reader, Application Administrator and Conditional Access Administrator. Common Azure RBAC built-in roles include Owner (full control plus the right to assign roles), Contributor (full control but no role assignment), Reader (view only) and User Access Administrator (manage role assignments only). There are also many service-specific roles such as Virtual Machine Contributor, Key Vault Secrets User and Storage Blob Data Reader. One bridge exists: a Global Administrator can turn on 'Access management for Azure resources', which grants them User Access Administrator at the root scope. It is meant for emergencies and should be switched off again.
An Azure RBAC role assignment has three parts: a security principal (user, group, service principal or managed identity), a role definition (the list of allowed operations) and a scope. Scopes form a hierarchy: management group, then subscription, then resource group, then individual resource. Permissions are inherited downward, so Reader on a management group gives read access to every subscription, resource group and resource beneath it. Effective permissions are the union of all assignments that apply, and Azure RBAC is additive: granting Reader does not take away Contributor granted elsewhere. Deny assignments exist but are created by Azure itself (for example by deployment stacks or managed applications), not directly by you.
Least privilege means giving each identity only the permissions it needs, at the narrowest scope, for only as long as needed. In practice: assign roles to groups rather than individuals, prefer a specific role (Virtual Machine Contributor) over a broad one (Contributor), assign at the resource group rather than the subscription when the work is limited to one application, and use Privileged Identity Management so that powerful roles are eligible rather than permanent. Limit the number of subscription Owners and Global Administrators, and keep a couple of break-glass accounts excluded from risky policies.
In the portal you manage Azure RBAC on the Access control (IAM) blade of any scope. The Check access tab shows what a principal can do there, and Role assignments shows who has what, including inherited assignments. Entra roles are managed under Microsoft Entra ID > Roles and administrators, and some can be scoped to an administrative unit so a helpdesk admin only manages users in one region.
Key terms
- Microsoft Entra role
- A directory role that grants permissions over identity objects and tenant settings, such as User Administrator or Security Administrator.
- Azure RBAC role
- A role definition that grants permissions over Azure resources through Azure Resource Manager, such as Owner, Contributor or Reader.
- Scope
- The level at which a role assignment applies: management group, subscription, resource group or resource; lower levels inherit it.
- User Access Administrator
- An Azure RBAC role that can manage role assignments but not the resources themselves.
- Least privilege
- Granting only the permissions needed, at the narrowest scope and for the shortest time.
A developer needs to restart VMs in the app-prod resource group. Instead of making them subscription Contributor, you add them to a group that holds Virtual Machine Contributor on that resource group only. They can manage those VMs but cannot touch networking in other resource groups or grant access to anyone else.
Check yourself
A Global Administrator cannot see any subscriptions. What is the supported way for them to gain access in an emergency?
Enable 'Access management for Azure resources' in the Entra ID properties, which grants User Access Administrator at the root scope; they can then assign themselves a role and should turn the setting off afterward.
A user has Reader at the subscription and Contributor on one resource group. What can they do in that resource group?
Contributor actions, because Azure RBAC is additive and effective permissions are the union of all applicable assignments.
Why assign roles to groups rather than individual users?
Group assignments are easier to review and change, reduce assignment sprawl and make joiner-mover-leaver changes a matter of group membership.