azure user management–restricting user roles
Users can be found under AAD in the Azure portal menu .
A subscription is the Umbrella for all resource groups.
Users can be OWNERS at a subscription level or at a Resource Group level.
To restrict access for a user, simply assign them ownership of a particular RG – and nothing else (remove them as subscription owner)
Roles
To get even more specific, you can define custom roles – to restrict a user to only ‘VM creation’
Leave a Reply