Type the name, or the common acronym, of the Azure authorisation system in which access is granted by assigning a role to a principal at a chosen scope.

Microsoft Certified: Azure Fundamentals (AZ-900), objective architecture-and-services. Azure architecture and services medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

Answer

Type the answer.

Accepted answers

Case insensitive.

Why

Role-based access control answers what an authenticated principal may do, by combining a security principal, a role definition and a scope into an assignment that is inherited downward. Two things it is not: it is not authentication, which happens earlier in Entra ID, and it is not a way to control sign-in conditions, which is Conditional Access. The default posture is no access until a role is assigned.

Where this comes from

Cited
Microsoft AZ-900 study guide skill area architecture-and-services.identity-access-security

Practise this

Reading one question is not practice. The trainer will draw a set from objective architecture-and-services and space the ones you get wrong.

Practise Microsoft Certified: Azure Fundamentals (AZ-900)

More questions on this objective

All questions on Azure architecture and services