QuestionQ61

Secure identity and access

You have an Azure subscription containing a resource group named RG1. RG1 contains a virtual machine named VM1 that uses Azure Active Directory (Azure AD) authentication.

Two custom Azure roles, Role1 and Role2, are scoped to RG1. Their permissions are shown here:

Question Image

Question Image

The roles are assigned to users as shown here:

Question Image

For each statement, select Yes if it is true; otherwise, select No.

Yes or No
StatementsYesNo
User1 can delete VM1.
User2 can delete VM1.
User3 can sign in to VM1 by using Azure AD credentials.
Explanation

Azure RBAC NotActions only carve out exclusions from the specific role definition they belong to; when a principal holds multiple role assignments, the effective permissions are the union of all assigned roles' allowed actions, so a delete permission granted by one role (Role2) is not blocked by a NotActions exclusion in a different assigned role (Role1) — this is why User2, who has both roles, can delete the VM even though User1, who has only Role1, cannot. Separately, Azure AD sign-in to a virtual machine is a data-plane operation controlled by dataActions (as used by the built-in Virtual Machine Administrator/User Login roles), and since both Role1 and Role2 have empty dataActions, no assignment of these roles grants the ability to log in to VM1 with Azure AD credentials.

Community Discussion

No comments yet. Be the first to start the discussion!