Microsoft Azure Administrator Associate AZ-104 Practice Question
You are an Azure administrator. Your developers need to manage virtual machines in a resource group but should not be able to modify virtual networks. What is the best way to accomplish this?
Use Azure PowerShell to create a custom role with 'New-AzRoleDefinition' and a JSON template.
Create an Azure Active Directory custom role with the necessary permissions.
Create a custom role in the Azure portal by cloning the 'Virtual Machine Contributor' role and removing network permissions.
Assign the 'Contributor' role to the developers at the resource group level.
Creating a custom role in the Azure portal by cloning the 'Virtual Machine Contributor' role and removing network permissions allows you to grant developers the exact permissions needed. This approach ensures they can manage virtual machines without the ability to modify virtual networks, adhering to the principle of least privilege. Using Azure PowerShell to create a custom role is an alternative, but the portal offers a more user-friendly and direct method in this scenario. Assigning the 'Contributor' role would grant excessive permissions beyond what is necessary, including network modifications. Azure Active Directory custom roles manage permissions within Azure AD and do not control access to Azure resources like virtual machines and networks.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does the principle of least privilege mean in Azure?
Open an interactive chat with Bash
What are custom roles in Azure and how do they differ from built-in roles?
Open an interactive chat with Bash
What is the 'Virtual Machine Contributor' role and what permissions does it provide?
Open an interactive chat with Bash
Microsoft Azure Administrator Associate AZ-104
Manage Azure identities and governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access