certslothcertsloth
SC-500/Topic 01

Azure / Associate

Microsoft Entra ID and Azure RBAC

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Entra identifies the principal; Azure RBAC authorises an action at a scope.

Must remember

  • A Microsoft Entra tenant is an identity directory. An Azure subscription is a billing/resource-management boundary associated with a tenant. Management groups organise subscriptions; resource groups organise resources. Do not treat tenant and subscription as synonyms.
  • Manage users, groups, properties, assigned licences and guest access deliberately. Security groups organise access; dynamic membership uses rules when licensing/features permit. B2B guests retain an external identity relationship. Self-service password reset needs appropriate eligibility, authentication methods and configuration.
  • An Azure role assignment is principal + role definition + scope. Scope can be management group, subscription, resource group or resource, with inheritance. Inspect effective assignments rather than only the nearest resource. Entra directory roles and Azure resource roles are different permission systems.
  • Owner can manage resources and access; Contributor manages resources but does not normally grant Azure roles; Reader reads management information. Data-plane roles, such as Storage Blob Data Reader, authorise data operations separately. Management-plane access is not always data access.
  • System-assigned managed identity follows one resource's lifecycle; user-assigned identity is an independent reusable resource. Both avoid embedded secrets for supported authentication. Grant the identity's service principal only the required target roles.
  • PIM supports time-bound/eligible privileged access; Conditional Access evaluates sign-in conditions and grant controls with appropriate licensing. MFA strengthens authentication; it does not create a missing resource role assignment. Keep a monitored emergency-access design.

Choose under exam pressure

Requirement Choice and reason
App needs storage access without stored credentials Managed identity plus an appropriate data role.
User can manage a storage account but cannot read blobs Check data-plane permissions.
Temporary privileged operations Eligible/time-bound access using PIM where available.

Traps

  • Entra administrator is not automatically Owner of every Azure subscription.
  • Contributor and Owner differ in access-management privileges.
  • A role at a parent scope can remain effective after a narrower assignment is removed.

Active recall

1. What are the three parts of a role assignment?

Principal, role definition and scope.

2. Which identity can be shared across several Azure resources?

A user-assigned managed identity, with deliberate lifecycle and permissions.

3. Does MFA grant access to a VM?

No. Authentication and authorisation remain separate.

4. Why inspect inherited roles?

An assignment at a parent scope can authorise access even if no local assignment exists.

5. What must be configured for SSPR?

Eligible users, permitted authentication methods and the relevant reset settings/licensing.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.