官术网_书友最值得收藏!

Role-based access control

After authenticating and gaining access to the Azure environment, there is an additional layer that checks for access authorization to the resource and resource group. This additional layer is role-based access control (RBAC), which checks whether the user who is trying to access the resource has permissions to access and perform the activity it intends to perform. It is composed of three different components:

  • Permissions: Also known as role definition
  • Scope: The scope on which the permissions are evaluated. They are resource groups and resources
  • Principal: The actor trying to access the resources. It could be a user, group, or a service principle

RBAC assigns permissions to a principle at a given scope. For example, contributor permission is assigned to a service principal for a resource group.

It is also hierarchical and flows down from subscription to the resource group, and finally to the resource level.

Any permissions assigned to a principal at a resource group scope automatically gets the same access for resources contained within that resource group.

主站蜘蛛池模板: 宁海县| 扎赉特旗| 吉隆县| 阳江市| 天津市| 山西省| 文成县| 本溪| 冀州市| 新平| 女性| 商南县| 开远市| 大悟县| 肇东市| 乌恰县| 西畴县| 东阿县| 沭阳县| 维西| 阿鲁科尔沁旗| 临清市| 武宣县| 河北区| 乐安县| 桐梓县| 晋中市| 象山县| 抚州市| 桐柏县| 哈密市| 饶河县| 饶平县| 青海省| 芜湖县| 邓州市| 永城市| 太保市| 东乡| 九龙坡区| 老河口市|