Attribute-based conditions added on top of Azure RBAC role assignments, such as granting access only to blobs carrying a certain index tag. Blobs (ADLS Gen2 included) and queues support them; Azure Files and Tables do not.
Also called attribute-based access control, ABAC, Role assignment conditions.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Azure ABAC in context, with comparison tables and the common traps.
Terms in this definition
- Azure RBAC
Azure's model for granting access: built-in or custom roles are assigned at a scope to users, groups or managed identities. Calling Foundry keylessly with Entra ID requires a data-plane role, for example Foundry User (formerly Azure AI User) or Cognitive Services OpenAI User.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Index
Speeds up queries that filter on certain columns by keeping those columns sorted, with pointers back to each row; the price is more storage and slower writes.
- Tag
Key-value label on compute (for cost tracking) or on a Unity Catalog securable or column, applied with
SET TAGorSET TAGSand requiringAPPLY TAG. Governed tags restrict allowed keys, values and assigners across the account. - ADLS Gen2
Short for Azure Data Lake Storage Gen2: a standard GPv2 account with hierarchical namespace turned on, so analytics workloads get true directories and POSIX-style ACLs.
- Azure Files
Azure's managed file shares over SMB or NFS. There is no Archive tier, and a single encryption key applies across the whole storage account.
Related terms
- AKS-ACR integration
Running az aks create or az aks update with --attach-acr grants AcrPull to a cluster's kubelet managed identity, letting nodes fetch images with no pull secrets. Registries using ABAC can't use this; grant Container Registry Repository Reader manually there.
- Blob index tags
Indexed, searchable key-value attributes set on blobs, which lifecycle rules can filter on via
blobIndexMatchand ABAC conditions can use; filtering by them isn't possible with a SAS. - Container Registry Repository Reader
A role for ACR registries with ABAC enabled that allows pulling and reading images, tags and metadata across the registry or only for repositories picked by ABAC conditions. It plays the part of AcrPull in ABAC mode but can't list the catalogue.
- Custom security attributes
An organisation's own key-value data for users and enterprise applications, kept in attribute sets and used to filter directory objects or to power Azure ABAC. Only the Attribute Definition and Attribute Assignment roles can work with them by default; a Global Administrator cannot.
- Delegated role assignment management with conditions
Sometimes called constrained delegation: someone gets a role that can write role assignments, such as Role Based Access Control Administrator, but an ABAC condition limits what they may hand out or take away, by role, by type of principal or by specific principal.
- Governed tags
Tags defined at account level and controlled by a tag policy that sets permitted values and who can apply them. Catalogs and schemas pass them down to child objects (columns do not inherit them), and ABAC policies use them as the attributes to match.
- Role assignment permissions mode
An ACR registry option that picks between RBAC Registry Permissions, using the classic AcrPull and AcrPush roles, and RBAC Registry + ABAC Repository Permissions, which adds roles scoped to repositories with ABAC conditions.
- Unity Catalog ABAC
Attribute-based access control: policies on catalogs, schemas or tables pick objects via governed tags and automatically enforce GRANT, DENY, column masks or row filters. Azure role-assignment conditions are something else.