In RBAC, which element defines "what permissions" are granted?
Choose an answer
Tap an option to check your answer.
Correct answer: Role Definition.
Why this is the answer
Role Definition specifies the collection of permissions that are granted. It outlines the specific actions (e.g., read, write, delete) that can be performed on Azure resources. For example, the "Contributor" role definition allows full access to manage all resources, but not to assign roles. Security Principal is the "who" — the user, group, service principal, or managed identity that is granted permissions. Scope is the "where" — the level at which the permissions apply (e.g., subscription, resource group, or resource). Identity Provider is a service that manages user identities and provides authentication, but it doesn't define the permissions themselves.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed