How can an organization apply role-based restrictions to Azure subscriptions while managing billing access separately?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure RBAC.
Why this is the answer
Azure RBAC (Role-Based Access Control) allows for fine-grained access management to Azure resources. You can assign specific roles (e.g., "Reader," "Contributor," "Owner") to users, groups, or service principals at different scopes (subscription, resource group, resource). This enables you to grant permissions for resource management while keeping billing access separate, as billing roles are distinct within RBAC. Azure Active Directory Groups are used to group users for easier RBAC assignment, but they don't define the permissions themselves. Azure Policy enforces rules and effects on resources, but it's not designed for granting or restricting direct access to resources or managing billing. Azure Management Groups are used to organize subscriptions into containers for governance at scale, not for direct access control or separate billing management.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed