This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Suppose a team member can't view resources in a resource group. Where would the administrator go to check the team member's access?
Check the team member's permissions by going to their Azure profile > My permissions.
Go to the resource group and select Access control (IAM) > Check Access.
Go to one of the resources in the resource group and select Role assignments.
Suppose an administrator in another department needs access to a virtual machine managed by your department. What's the best way to grant them access to just that resource?
At the resource scope, create a role for them with the appropriate access.
At the resource group scope, assign the role with the appropriate access.
At the resource scope, assign the role with the appropriate access.
Suppose a developer needs full access to a resource group. If you are following least-privilege best practices, what scope should you specify?
Resource
Resource group
Subscription
Suppose an administrator needs to generate a report of the role assignments for the last week. Where in the Azure portal would they generate that report?
Search for Activity log and filter on the Create role assignment (roleAssignments) operation.
At the appropriate scope, go to Access control (IAM) > Download role assignments.
At the appropriate scope, go to Access control (IAM) > Role assignments.
You must answer all questions before checking your work.
Was this page helpful?