Gives access in Azure RBAC by binding three things together: who (a security principal), what (a role definition) and where (a scope).
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Role assignment in context, with comparison tables and the common traps.
Terms in this definition
- Azure RBAC
Azure's model for granting access: built-in or custom roles are assigned at a scope to users, groups or managed identities. Calling Foundry keylessly with Entra ID requires a data-plane role, for example Foundry User (formerly Azure AI User) or Cognitive Services OpenAI User.
- Binding
A declarative way to bring data into a function as an input or to write results out as an output. None are required: the code is always free to talk to the target service by using an SDK client from Azure.
- Security principal
Identity that a role assignment grants access to. It can be a user, a group, a managed identity or a service principal, which represents an application.
- Role definition
A set of permissions, for example read, write and delete, that is either built in (Owner, Contributor, Reader and others) or custom. People normally just call it a role.
- WHERE
Limits a SELECT, UPDATE or DELETE to just the rows meeting a condition. Omit it, and the statement hits every row.
- Scope
Where an access or policy assignment takes effect. It can be set on a single resource, a resource group, a subscription or a management group, and settings flow down from higher levels.
Related terms
- Administrative unit
Used to confine a role assignment to a subset of a Microsoft Entra directory, such as just one region's users for a local helpdesk. A unit holds users, groups or devices; units cannot be nested, and including a group does not make its individual members part of the scope.
- Cosmos DB Built-in Data Contributor
A native data-plane role in Azure Cosmos DB. Whoever holds it can read metadata, run queries, read the change feed and perform full create, read, update and delete on items; grant it via az cosmosdb sql role assignment create.
- Deny assignments
Azure RBAC entries that block actions even where a role assignment allows them. Once only Azure services such as deployment stacks made them; users can now create them too (New-AzDenyAssignment or az role deny-assignment create), covering write, delete and action operations but not groups.
- Eligible assignment
A role assignment in PIM that has no effect until the user activates it, satisfying whatever MFA, justification or approval is required.
- Expose an API
Part of an app registration where you set the Application ID URI and the delegated scopes clients can request. Platforms, token claims and app role assignment are configured elsewhere.
- HTTP 403 Forbidden
The status returned when the caller has authenticated but is blocked, either because the identity is missing a needed role or because the network denies it. Running az login with no data-plane role assignment is a common cause.
- Scope groups
Under an Intune role assignment, the set of users and devices an administrator is permitted to manage.
- Security Admin
Built-in Azure role whose holders manage security policy, alerts and recommendations in Microsoft Defender for Cloud. Role assignment and the creation of general policy definitions fall outside what it allows.