官术网_书友最值得收藏!

Role-based access control

After authenticating and gaining access to the Azure environment, there is an additional layer that checks for access authorization to the resource and resource group. This additional layer is role-based access control (RBAC), which checks whether the user who is trying to access the resource has permissions to access and perform the activity it intends to perform. It is composed of three different components:

  • Permissions: Also known as role definition
  • Scope: The scope on which the permissions are evaluated. They are resource groups and resources
  • Principal: The actor trying to access the resources. It could be a user, group, or a service principle

RBAC assigns permissions to a principle at a given scope. For example, contributor permission is assigned to a service principal for a resource group.

It is also hierarchical and flows down from subscription to the resource group, and finally to the resource level.

Any permissions assigned to a principal at a resource group scope automatically gets the same access for resources contained within that resource group.

主站蜘蛛池模板: 沿河| 北川| 安陆市| 安阳县| 黄山市| 文登市| 都江堰市| 安徽省| 梁平县| 安龙县| 长寿区| 湘阴县| 德保县| 四会市| 龙泉市| 舒城县| 盖州市| 红原县| 台南市| 萨嘎县| 方正县| 镇雄县| 临城县| 安溪县| 英超| 务川| 太保市| 呈贡县| 萨迦县| 邯郸县| 额济纳旗| 邻水| 和政县| 滨州市| 绥滨县| 河北省| 阳城县| 深州市| 阳原县| 富顺县| 青岛市|