Elevate Access Global Admin Role
Azure AD
Admin roles
Azure Active
Directory tenant
Global admin/User Access Admin
/ Root (elevated access)
Azure RBAC
roles Root
Management Group
Management Group
Subscription
Resource Group
Resource
https://docs.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin 1
Azure Subscription Management
Management
Groups
Subscriptions
Resource
Groups
Resources
2
Key Azure Governance Technologies - BRK2021 - Azure security & management
"policyRule": {
"if": {
"not": {
"field": "location",
"in":
Resources RBAC
"[parameters('listOfAllowedLocations
')]"
}
},
"then": { Policies
"effect": "Deny"
}
}
Policy Blueprints Management Groups
Enforce or audit rules to Quickly create multiple subscriptions Map your organizational structure into
ensure compliance. with resources, policies and users Azure to enable governance in multi-
already setup. tenant and cross-regional scenarios
Azure Resource Manager + Azure Resource Graph