官术网_书友最值得收藏!

Built-in roles

Azure offers various built-in roles that you can use for assigning permissions to users, groups, and applications. RBAC offers the following three standard roles that you can assign to each Azure resource:

  • Owner: Users in this role can manage everything, and can create new resources.
  • Contributor: Users in this role can manage everything, just like users in the owner role, but they can't assign access to others.
  • Reader: Users in this role can read everything, but they are not allowed to make any changes.

Aside from the standard roles, each Azure resource also has roles that are scoped to particular resources. For instance, you can assign users, groups, or applications to the SQL security manager, from which they can manage all security-related policies of the Azure SQL Server, or you can assign them to the VM contributor role, where they can manage the VMs, but not the VNet or storage accounts that are connected to a VM.

For an overview of all the built-in roles that Azure offers, you can refer to  https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles.

While these built-in roles usually cover all possible use cases, they can never account for every requirement in an organization. To allow for flexibility in role assignment, RBAC provides the ability to make custom roles. Let's look at this feature.

主站蜘蛛池模板: 巨鹿县| 曲松县| 晋江市| 余姚市| 北海市| 巧家县| 禄劝| 清水河县| 太湖县| 车致| 长汀县| 东宁县| 曲水县| 安康市| 德化县| 静乐县| 许昌市| 桃园市| 龙泉市| 蓬莱市| 辽中县| 达尔| 庆安县| 锦屏县| 高清| 营山县| 柞水县| 弥勒县| 谷城县| 酉阳| 老河口市| 陵川县| 巴南区| 康马县| 阳曲县| 周口市| 江门市| 金川县| 太湖县| 大同县| 土默特左旗|