Azure RBAC Explained: Roles, Scope, and Why Least Privilege Breaks Down
ID: d88744f4-b83f-52b4-a8fc-5111f5eae5c5
STIX ID: report--d88744f4-b83f-52b4-a8fc-5111f5eae5c5
Feed Name: Security Boulevard
This blog post explains how Azure RBAC works (principal + role + scope = effective access), why standing and overly broad role assignments degrade least privilege over time, and the risks posed by service principals and managed identities; it recommends scoping roles narrowly, using PIM and ABAC, auditing dormant non-human identities, and adopting usage-based enforcement (as offered by Sonrai) to maintain least privilege at scale.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
