Azure RBAC entries that block actions even where a role assignment allows them. Once only Azure services such as deployment stacks made them; users can now create them too (New-AzDenyAssignment or az role deny-assignment create), covering write, delete and action operations but not groups.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Deny assignments in context, with comparison tables and the common traps.
Terms in this definition
- Azure RBAC
Azure's model for granting access: built-in or custom roles are assigned at a scope to users, groups or managed identities. Calling Foundry keylessly with Entra ID requires a data-plane role, for example Foundry User (formerly Azure AI User) or Cognitive Services OpenAI User.
- WHERE
Limits a SELECT, UPDATE or DELETE to just the rows meeting a condition. Omit it, and the statement hits every row.
- Role assignment
Gives access in Azure RBAC by binding three things together: who (a security principal), what (a role definition) and where (a scope).
- Deployment stacks
Azure resources treating a set of jointly deployed resources as a single managed unit; together with Template Specs they replace Blueprints.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
Related terms
- Azure Deployment Stack Contributor
Can manage deployment stacks, but has no right to add or remove deny assignments; an Azure built-in role.
- Deny settings
On a deployment stack, DenyDelete or DenyWriteAndDelete applies deny assignments to the managed resources that bind every principal, Owners too, apart from any excluded.