Sometimes called constrained delegation: someone gets a role that can write role assignments, such as Role Based Access Control Administrator, but an ABAC condition limits what they may hand out or take away, by role, by type of principal or by specific principal.
Also called constrained delegation.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Delegated role assignment management with conditions in context, with comparison tables and the common traps.
Terms in this definition
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Role Based Access Control Administrator
Role able to add and remove role assignments (
roleAssignments/write) but not to manage resources. Along with Owner and User Access Administrator, it is one of the roles that can assign roles. - Azure ABAC
Attribute-based conditions added on top of Azure RBAC role assignments, such as granting access only to blobs carrying a certain index tag. Blobs (ADLS Gen2 included) and queues support them; Azure Files and Tables do not.
- Principal
A user, group or service principal: anything that can receive a privilege grant.
Related terms
- msDS-AllowedToActOnBehalfOfOtherIdentity
Under resource-based constrained delegation, this attribute on the target account names who may delegate to it. In PowerShell it is populated through PrincipalsAllowedToDelegateToAccount.
- RBCD
Resource-based constrained delegation. Configured with PowerShell on the back-end account instead of the front-end service, it has existed since Windows Server 2012 and can cross domains.
See Delegated role assignment management with conditions in the full glossary