Jump into concepts and practice - no test required
or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Recall & Review
beginner
What is an Access Policy in Azure?
An Access Policy in Azure defines specific permissions for a resource, like a key vault, controlling who can perform certain actions such as read or write.
Click to reveal answer
beginner
What does RBAC stand for and what is its purpose?
RBAC stands for Role-Based Access Control. It assigns roles to users or groups to control access to Azure resources based on their job functions.
Click to reveal answer
intermediate
How does RBAC differ from Access Policies in Azure?
RBAC controls access at the Azure resource level using roles, while Access Policies are specific to certain services like Key Vault and control permissions at a finer level.
Click to reveal answer
intermediate
Can RBAC and Access Policies be used together in Azure?
Yes, RBAC manages who can access the resource itself, and Access Policies manage what actions they can perform inside that resource, like keys or secrets in a Key Vault.
Click to reveal answer
beginner
Give a real-life example to explain RBAC vs Access Policies.
Think of RBAC as giving someone a key to a building (resource access). Access Policies are like rules inside the building that say which rooms they can enter or what they can do there.
Click to reveal answer
What does RBAC control in Azure?
AWho can access Azure resources based on roles
BSpecific permissions inside a Key Vault
CNetwork traffic rules
DBilling and subscription settings
✗ Incorrect
RBAC controls access to Azure resources by assigning roles to users or groups.
Access Policies in Azure are mainly used with which service?
AAzure Virtual Machines
BAzure Key Vault
CAzure Storage Accounts
DAzure Active Directory
✗ Incorrect
Access Policies are commonly used to control permissions inside Azure Key Vault.
Which statement is true about RBAC and Access Policies?
AThey are the same and interchangeable
BAccess Policies control resource access; RBAC controls actions inside the resource
CRBAC controls resource access; Access Policies control actions inside the resource
DBoth control network access
✗ Incorrect
RBAC manages who can access resources; Access Policies manage what actions can be done inside certain resources.
Can a user have access to a resource via RBAC but be blocked by Access Policies?
AYes, but only for network resources
BNo, RBAC overrides Access Policies
CNo, Access Policies override RBAC
DYes, RBAC grants access but Access Policies can restrict specific actions
✗ Incorrect
A user may have resource access through RBAC but be limited by Access Policies on what they can do inside.
Which is a benefit of using RBAC over Access Policies?
ARBAC provides broad role assignments across many resources
Hint: Key vault secrets need access policies, not just RBAC [OK]
Common Mistakes:
Assuming RBAC alone controls key vault secrets
Thinking subscription-level RBAC restricts access
Believing portal restart fixes permission issues
5. You want to secure an Azure Key Vault so that only a specific user can read secrets, and a group can manage keys. Which approach follows best practices?
hard
A. Assign specific RBAC roles to the user for secret read (Key Vault Secrets User) and to the group for key management (Key Vault Crypto Officer).
B. Create an access policy granting the user secret read permission; assign an RBAC role to the group for key management.
C. Use access policies for both user and group to grant all permissions.
D. Assign the user an RBAC role for secrets and the group an access policy for keys.
Solution
Step 1: Choose RBAC as best practice
Azure recommends RBAC for Key Vault. Disable access policies and enable RBAC authorization on the Key Vault.
Step 2: Assign granular roles at Key Vault scope
Assign 'Key Vault Secrets User' role to user (get/list secrets). Assign 'Key Vault Crypto Officer' role to group (manage keys).
Final Answer:
Assign specific RBAC roles to the user for secret read (Key Vault Secrets User) and to the group for key management (Key Vault Crypto Officer). -> Option A
Quick Check:
RBAC Secrets User + Crypto Officer roles [OK]
Hint: RBAC best practice: Secrets User + Crypto Officer roles [OK]
Common Mistakes:
Trying to mix Access Policies and RBAC (not possible)
Using access policies for everything (legacy method)