Resource scope
Before you assign an Azure RBAC role to a security principal, determine the scope of access that the security principal should have. Best practices dictate that it's always best to grant only the narrowest possible scope. Azure RBAC roles defined at a broader scope are inherited by the resources beneath them.
You can scope access to Azure queue resources at the following levels, beginning with the narrowest scope:
- An individual queue. At this scope, a role assignment applies to messages in the queue, and to queue properties and metadata.
- The storage account. At this scope, a role assignment applies to all queues and their messages.
- The resource group. At this scope, a role assignment applies to all of the queues in all of the storage accounts in the resource group.
- The subscription. At this scope, a role assignment applies to all of the queues in all of the storage accounts in all of the resource groups in the subscription.
- A management group. At this scope, a role assignment applies to all of the queues in all of the storage accounts in all of the resource groups in all of the subscriptions in the management group.
Comments
Post a Comment