How can a company limit developers so they can manage only virtual machines but not storage or networking resources in Azure?
Choose an answer
Tap an option to check your answer.
Correct answer: Role-Based Access Control (RBAC).
Why this is the answer
Role-Based Access Control (RBAC) is the correct solution because it allows you to define granular permissions for users and groups at various scopes (subscription, resource group, or individual resource). With RBAC, you can assign built-in or custom roles that grant specific permissions, such as "Virtual Machine Contributor," which allows management of virtual machines but restricts access to other resource types like storage accounts or virtual networks. Azure Blueprints are used for deploying and updating environments consistently, not for fine-grained access control. Azure Policy enforces organizational standards and assesses compliance, but it doesn't directly manage who can perform actions on specific resources. Azure Resource Locks prevent accidental deletion or modification of resources, rather than defining user permissions.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed