What's the best way to grant a team permission to only start and stop VMs in a specific resource group?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Custom RBAC role with specific actions.
Why this is the answer
Creating a Custom RBAC role with specific actions for starting and stopping VMs in a particular resource group is the most precise and secure method. This adheres to the principle of least privilege, granting only the necessary permissions. Assigning the Contributor role at the subscription level would give the team far too many permissions across all resources in the subscription, violating least privilege. Applying a ReadOnly lock on the VM would prevent any modifications, including starting or stopping, which is the opposite of the requirement. Granting the Owner role on the resource group would give full control over all resources within that group, exceeding the requested permissions.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed