0% found this document useful (0 votes)
56 views3 pages

Elevate Access Global Admin Role: Azure AD Admin Roles Azure Active Directory Tenant

This document discusses the elevated access global admin role in Azure Active Directory which provides the highest level of access across Azure subscriptions, resource groups, and resources. It has root management capabilities across the Azure AD tenant, subscriptions, and management groups. The global admin role can access all resources without permission limitations compared to standard Azure RBAC roles which have more constrained access.

Uploaded by

bouga2
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
56 views3 pages

Elevate Access Global Admin Role: Azure AD Admin Roles Azure Active Directory Tenant

This document discusses the elevated access global admin role in Azure Active Directory which provides the highest level of access across Azure subscriptions, resource groups, and resources. It has root management capabilities across the Azure AD tenant, subscriptions, and management groups. The global admin role can access all resources without permission limitations compared to standard Azure RBAC roles which have more constrained access.

Uploaded by

bouga2
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
You are on page 1/ 3

Elevate Access Global Admin Role

Azure AD
Admin roles
Azure Active
Directory tenant

Global admin/User Access Admin


/ Root (elevated access)

Azure RBAC
roles Root
Management Group

Management Group

Subscription

Resource Group

Resource

https://docs.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin 1
Azure Subscription Management

Management
Groups

Subscriptions

Resource
Groups

Resources

2
Key Azure Governance Technologies - BRK2021 - Azure security & management

"policyRule": {
"if": {
"not": {
"field": "location",
"in":
Resources RBAC
"[parameters('listOfAllowedLocations
')]"
}
},
"then": { Policies
"effect": "Deny"
}
}

Policy Blueprints Management Groups


Enforce or audit rules to Quickly create multiple subscriptions Map your organizational structure into
ensure compliance. with resources, policies and users Azure to enable governance in multi-
already setup. tenant and cross-regional scenarios

Azure Resource Manager + Azure Resource Graph

You might also like