官术网_书友最值得收藏!

Role-based access control

After authenticating and gaining access to the Azure environment, there is an additional layer that checks for access authorization to the resource and resource group. This additional layer is role-based access control (RBAC), which checks whether the user who is trying to access the resource has permissions to access and perform the activity it intends to perform. It is composed of three different components:

  • Permissions: Also known as role definition
  • Scope: The scope on which the permissions are evaluated. They are resource groups and resources
  • Principal: The actor trying to access the resources. It could be a user, group, or a service principle

RBAC assigns permissions to a principle at a given scope. For example, contributor permission is assigned to a service principal for a resource group.

It is also hierarchical and flows down from subscription to the resource group, and finally to the resource level.

Any permissions assigned to a principal at a resource group scope automatically gets the same access for resources contained within that resource group.

主站蜘蛛池模板: 宁南县| 福鼎市| 佛冈县| 建湖县| 关岭| 保靖县| 读书| 布拖县| 丹寨县| 枞阳县| 两当县| 杂多县| 柳林县| 济源市| 获嘉县| 巴楚县| 黄浦区| 西充县| 蓬溪县| 堆龙德庆县| 山东| 孟村| 孟村| 南阳市| 乐亭县| 闸北区| 宾川县| 永新县| 定兴县| 怀集县| 辽源市| 白玉县| 成安县| 旌德县| 托里县| 宁陵县| 和龙市| 东乡| 红原县| 上栗县| 青州市|