Short for role-based access control: Azure role assignments, inherited downward through scopes, that decide who may perform which actions on resources. Resource location and size are outside its control.
Also called role-based access control.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500AI-300AI-103AZ-900AI-200DP-900DP-750SC-900AB-900SC-200SC-300AZ-400AZ-802DP-600SC-401MD-102DP-800ALZ
Each book explains RBAC in context, with comparison tables and the common traps.
Terms in this definition
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- CONTROL
Granting this on a securable gives all other permissions on it too, making it the most powerful SQL permission. At database scope that includes UNMASK and ALTER ANY MASK. Warehouse access through the Admin, Member or Contributor workspace roles carries it.
Related terms
- AD DS authentication (Azure Files)
Option that domain-joins a storage account to on-premises AD DS, letting synced hybrid users mount its SMB shares using Kerberos. RBAC controls share-level access, while Windows ACLs govern files and folders.
- Azure Governance Visualizer
An open-source script that produces a report on a tenant's governance setup, including management groups, policy and RBAC, and highlights Azure landing zone policies that are out of date or obsolete. The Architecture Center offers an accelerator for running it.
- Canary management group hierarchy
A test copy of your live landing zone structure, with canary in each ID and placed directly beneath the root, that you can switch on if wanted. Policy, RBAC and subscription placement changes are tried there first, then promoted.
- Copilot in Intune
Puts Security Copilot inside Intune's admin center. Admins can ask questions of their data in plain English, get policy and device summaries, and have device query KQL drafted for them; it consumes Security Copilot compute units, and scope tags and RBAC still apply.
- Cosmos DB Built-in Data Reader
Data-plane RBAC role native to Cosmos DB that lets Microsoft Entra ID tokens be used to read data.
- Find-RoleCapability
Searches for JEA (Just Enough Administration) role capabilities; this PowerShellGet cmdlet is unrelated to Azure role-based access control.
- Foundry control plane and data plane
The two halves of Foundry's RBAC model. Control plane actions cover resource settings, networking, deployments and project creation, whereas data plane actions cover work inside a project such as building agents, running evaluations and uploading files.
- IAM
Short for identity and access management. The Azure portal's Access control (IAM) blade is where RBAC roles are assigned.