Role able to add and remove role assignments (roleAssignments/write) but not to manage resources. Along with Owner and User Access Administrator, it is one of the roles that can assign roles.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Role Based Access Control Administrator in context, with comparison tables and the common traps.
Terms in this definition
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Architecture Definition Document
A key deliverable bringing together the main architecture artifacts across the four domains for every relevant state: baseline, transition and target. It sets out, in qualitative terms, what the architect intends.
- MANAGE
A Unity Catalog privilege allowing a principal to grant and revoke access on an object, hand over its ownership and drop it, all without being the owner. It gives no data access by itself and is not part of
ALL PRIVILEGES. - Full control
Gives every right over protected content, EXTRACT included, plus the ability to alter or strip the encryption. Owners and the Rights Management issuer always hold it.
- User Access Administrator
Granted Microsoft.Authorization/* actions, this Azure role handles role assignments and management locks, yet it can't write tags or manage any other resources. For creating or removing locks, no less-privileged role suffices.
Related terms
- Delegated role assignment management with conditions
Sometimes called constrained delegation: someone gets a role that can write role assignments, such as Role Based Access Control Administrator, but an ABAC condition limits what they may hand out or take away, by role, by type of principal or by specific principal.
See Role Based Access Control Administrator in the full glossary