Azure has two separate role systems. Azure roles control resources; Microsoft Entra roles control the directory. Scopes and inheritance, Owner vs Contributor vs User Access Administrator, elevate access, and three traps.
By Tony Rough
Two questions catch people out:
Because Azure has two separate role systems, and by default neither grants anything in the other.
| Azure roles (Azure RBAC) | Microsoft Entra roles | |
|---|---|---|
| Control | Azure resources: management groups, subscriptions, resource groups, resources | The directory: users, groups, app registrations, licences, domains |
| Assigned at | Management group, subscription, resource group or single resource | The whole tenant, an administrative unit or a single object |
| Where you see them | Access control (IAM) on any scope | Roles and administrators in the Entra admin center |
An Azure role assignment is three things: who (a user, group, service principal or managed identity), what (a role definition) and where (a scope). Assignments are inherited downwards: Contributor on a resource group applies to everything inside it, and an assignment on a management group applies to every subscription beneath it.
The roles that matter most:
| Role | Manage resources | Assign roles |
|---|---|---|
| Owner | ✓ | ✓ |
| Contributor | ✓ | ✗ |
| Reader | read only | ✗ |
| User Access Administrator | read only | ✓ |
| Role Based Access Control Administrator | read only | ✓, and can be limited by conditions |
The rule of thumb: assign the least powerful role at the narrowest scope that does the job.
Entra roles manage the directory itself:
Least privilege applies here too: pick the narrowest role, and scope it to an administrative unit when someone should only manage part of the organisation.
A Global Administrator can turn on Access management for Azure resources (Microsoft Entra ID → Properties). That elevates their access: they’re given User Access Administrator at the root scope (/), which covers every management group and subscription in the tenant. From there they can grant themselves or others whatever Azure roles are needed.
It’s a recovery tool (for example, regaining access to a subscription whose owners have left) and it applies only to the person who switches it on. Microsoft’s guidance is to switch it off again once the change is made.
| You need… | Choose |
|---|---|
| Rights over Azure resources (VMs, storage, networks) | An Azure role, at the narrowest scope |
| Rights over users, groups, passwords or licences | A Microsoft Entra role |
| Manage resources, but not access | Contributor |
| Manage access, but not resources | User Access Administrator |
| A Global Administrator locked out of a subscription | Elevate access, then switch it off |
Azure RBAC is chapter 2 of the AZ-104 study guide, with Entra users and groups in chapter 1. Entra roles versus Azure RBAC and elevate access are covered in the governance chapter (chapter 4) of the SC-500 study guide, and identity design in chapter 1 of the AZ-305 study guide. Facts checked against Microsoft Learn on 4 October 2026.
Both lock an Azure service down to your virtual network, but they work in completely different ways. How each one works, the on-premises trap, DNS, data exfiltration, and a five-second way to choose.
Four Azure services balance traffic, and two questions tell them apart: is it web traffic that needs layer 7, and is it regional or global? Each service on a 2x2 grid, plus three exam traps.
Six redundancy options, four acronyms and one trap that catches almost everyone. The two questions that pick the right Azure Storage option every time, plus the read-access trap and three more.
Microsoft has pushed the retirement of Application Insights URL ping tests back to September 2028 and announced that Azure IoT Central retires in September 2029. Automatic zone placement for scale sets, and Microsoft Entra Kerberos for Azure NetApp Files, are now in preview.
Four Microsoft certification study guides are out, three more are on the way, and there's now a free glossary for the whole series. Here's what the books are, how they're different, and what's free on this site.