How resource locks prevent accidental deletion or change, how they inherit, and how they differ from RBAC and Policy.
From Ultra Transcenders AZ-900 by Tony Rough (publishing soon)
Even people with the right permissions make mistakes, such as deleting the wrong resource group. A resource lock protects a subscription, resource group or resource from accidental deletion or modification, and it overrides user permissions.
| Lock (portal name / command-line name) | Read | Modify | Delete |
|---|---|---|---|
| Delete / CanNotDelete | Yes | Yes | No |
| Read-only / ReadOnly | Yes | No | No |
Key behaviour:
Microsoft.Authorization/locks/* permissions, such as Owner and User Access Administrator.One-line CLI example: az lock create --name LockGroup --lock-type CanNotDelete --resource-group rg-app
Common trap: Believing an Owner can delete a resource that has a Delete lock - locks apply regardless of RBAC role; even an Owner must remove the lock first.
Common trap: Relying on a lock to protect the data stored in a resource - locks apply only to control-plane (management) operations; data-plane operations such as deleting blobs or database rows are not blocked.
This note is one section of Ultra Transcenders AZ-900: Microsoft Azure Fundamentals, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Publishing soon on Amazon in Kindle and paperback editions.
About the book · AZ-900 terms in the glossary · All AZ-900 study notes
Which security and management duties Microsoft owns, which you always keep, and which shift by service type.
What each cloud service type gives you, what you still manage, and typical use cases for each.
What sovereign regions are, who can use them, and how they differ from the public Azure regions.
How peering connects virtual networks within and across regions, and what traffic and transitivity rules apply.
How each storage redundancy option copies your data and which failures it protects against.
The three Zero Trust principles and how they change the traditional network-perimeter approach to security.
What Azure Advisor recommends across its categories and how it fits alongside Service Health and Azure Monitor.