AZ-104 Question 29
Single answerYou manage an Azure subscription that contains several resource groups, including one named RG-Data. A user named Karim has the 'Reader' role assigned at the subscription scope, but also has the 'Contributor' role assigned specifically for RG-Data. Another user, Alicia, has no role at the subscription level but is assigned the 'Owner' role for RG-Data. Which statement accurately reflects their effective permissions for resources in RG-Data and at the subscription level?
- A
Karim can only view resources in RG-Data, while Alicia can manage RG-Data but not resources elsewhere in the subscription.
- B
Karim can create and manage resources in RG-Data, while Alicia has read-only access to RG-Data.
- C
Karim can manage RG-Data because the Contributor role at the resource group level overrides the Reader role at the subscription. Alicia can also fully manage RG-Data as Owner.
- D
Karim and Alicia both have full control at the subscription scope because roles assigned at a lower scope grant subscription-wide privileges.
Show answer and explanation
Correct answer: C
Explanation
Role assignments at a more specific scope (resource group) override broader-scope assignments when determining effective permissions on that resource group. Karim’s Contributor role in RG-Data grants him create and modify rights there despite his Reader role at the subscription level. Alicia’s Owner role in RG-Data gives her full control over that resource group but does not extend to the entire subscription.
- A. Incorrect.
Even though Karim has Reader at the subscription level, his Contributor role at the resource group allows him more than read-only access. So this statement is incorrect.
- B. Incorrect.
While Karim does gain Contributor permissions in RG-Data, Alicia’s Owner role offers more than read-only. Hence, this is incorrect.
- C. Correct.
This is correct. Karim’s Contributor role overrides his Reader role in the specific scope of RG-Data, and Alicia, as Owner, can also manage all resources in RG-Data.
- D. Incorrect.
Azure RBAC roles do not escalate to a higher scope; having a role at the resource group level does not grant subscription-wide access. This statement is incorrect.