AZ-500 CHƯƠNG 03 5 Labs Least Privilege

RBAC, Custom Roles & Privileged Identity Management

Phân quyền chính xác theo scope, tạo custom role với least privilege, kiểm soát quyền cao bằng PIM eligible assignment và access review định kỳ.

🎯 Mục tiêu chương

  • Phân biệt Entra role và Azure RBAC role.
  • Gán quyền theo scope: management group, subscription, resource group, resource.
  • Tạo custom role với nguyên tắc least privilege.
  • Cấu hình Privileged Identity Management (PIM) eligible assignment.
  • Thực hiện Access Review định kỳ.

📚 Nội dung chi tiết

3.1 Azure RBAC

Built-in Role Quyền hạn Scope điển hình
OwnerToàn quyền kể cả gán roleSubscription / RG
ContributorTạo/sửa/xóa resource, không gán roleRG / Resource
ReaderChỉ xem, không thay đổiSubscription / RG
Security ReaderXem security state, không thay đổiSubscription
Security AdminXem và sửa security policySubscription
User Access AdminChỉ quản lý role assignmentSubscription
Scope Hierarchy: Management Group → Subscription → Resource Group → Resource. Role gán ở scope cha kế thừa xuống scope con. Deny assignment (từ Blueprint/Policy) override Allow.

3.2 Entra Roles vs Azure RBAC

Microsoft Entra Roles
  • • Quản lý danh tính trong Entra ID
  • • Global Administrator — toàn quyền tenant
  • • Privileged Role Administrator — quản lý role
  • • Security Administrator — chính sách bảo mật
  • • User Administrator — quản lý user/group
Azure RBAC Roles
  • • Quản lý tài nguyên Azure
  • • Gán tại scope: MG, Sub, RG, Resource
  • • Kế thừa từ scope cha
  • • Độc lập với Entra roles

3.3 Custom Roles

Tạo custom role khi built-in role không đủ chi tiết để áp dụng least privilege.

JSON — Custom Role Definition
{
  "Name": "VM Restart Operator",
  "Description": "Chỉ cho phép restart VM",
  "Actions": [
    "Microsoft.Compute/virtualMachines/restart/action",
    "Microsoft.Compute/virtualMachines/read",
    "Microsoft.Resources/subscriptions/resourceGroups/read"
  ],
  "NotActions": [],
  "DataActions": [],
  "NotDataActions": [],
  "AssignableScopes": [
    "/subscriptions/{subscription-id}"
  ]
}
Actions: Thao tác được phép (control plane)
NotActions: Loại trừ khỏi Actions
DataActions: Thao tác trên data plane
AssignableScopes: Phạm vi có thể gán role

3.4 Privileged Identity Management (PIM)

PIM thực thi nguyên tắc Just-in-Time (JIT) access — không cấp quyền cao thường trực, chỉ kích hoạt khi cần thiết.

Eligible Assignment

User có quyền nhưng chưa active. Phải kích hoạt mới có hiệu lực.

Active Assignment

Quyền luôn active, không cần kích hoạt. Chỉ dùng khi thực sự cần.

Approval Workflow

Kích hoạt quyền cao cần được approver phê duyệt trước khi có hiệu lực.

PIM cần Entra ID P2. Khi kích hoạt: MFA required, justification, activation duration (tối đa theo policy), audit history đầy đủ.

3.5 Access Reviews

Mục đích
  • • Rà soát quyền định kỳ (hàng tháng/quý)
  • • Review group membership
  • • Review guest access (B2B)
  • • Auto-apply result: tự xóa quyền không cần thiết
Quy trình
  • 1. Tạo Access Review (scope, reviewer, thời gian)
  • 2. Reviewer approve/deny từng thành viên
  • 3. Apply kết quả tự động hoặc thủ công
  • 4. Kiểm tra audit log

🧪 Lab trong chương

✅ Checklist cuối chương

Zalo