Reader small image

You're reading from  Exam Ref AZ-304 Microsoft Azure Architect Design Certification and Beyond

Product typeBook
Published inJul 2021
PublisherPackt
ISBN-139781800566934
Edition1st Edition
Right arrow
Author (1)
Brett Hargreaves
Brett Hargreaves
author image
Brett Hargreaves

Brett Hargreaves is a principal Azure consultant for Iridium Consulting, who has worked with some of the world's biggest companies, helping them design and build cutting-edge solutions. With a career spanning infrastructure, development, consulting, and architecture, he's been involved in projects covering the entire solution stack using Microsoft technologies. He loves passing on his knowledge to others through books, blogging, and his online training courses.
Read more about Brett Hargreaves

Right arrow

Chapter 4

Management groups are a great way of granting roles to users in a hierarchical manner that fits a company's geographical or divisional structure. In this scenario, the Global Administrator role would be set at the root tenant-level; however, for each region, a nominated administrator account could be set as Owner that only applied to a geographic management group.

Further service line groups could then be set within each country where the Owner Azure Role could be set on nominated IT Champions. The structure would look as follows:

Example RBAC hierarchy

To apply the least privileged principle, AD Manager roles (such as User Administrator) would be assigned to users as an eligible role, with the IT Champion set as the approver. Yearly access reviews would also be applied to these roles.

Create risk policies that deny access should a score of high be met, and a separate policy to force a password change on medium and above.

Finally, to support these actions...

lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
Exam Ref AZ-304 Microsoft Azure Architect Design Certification and Beyond
Published in: Jul 2021Publisher: PacktISBN-13: 9781800566934

Author (1)

author image
Brett Hargreaves

Brett Hargreaves is a principal Azure consultant for Iridium Consulting, who has worked with some of the world's biggest companies, helping them design and build cutting-edge solutions. With a career spanning infrastructure, development, consulting, and architecture, he's been involved in projects covering the entire solution stack using Microsoft technologies. He loves passing on his knowledge to others through books, blogging, and his online training courses.
Read more about Brett Hargreaves