Manage custom roles, including Azure roles and Microsoft Entra roles (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage identity, access, and governance (20–25%)
   --> Implement governance to enforce security and regulatory compliance
      --> Manage custom roles, including Azure roles and Microsoft Entra roles


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Role-based access control (RBAC) is a fundamental component of cloud security. Rather than granting users unrestricted administrative privileges, RBAC allows an organization to assign only the permissions required to perform a particular job.

Azure and Microsoft Entra ID both support custom roles, but they are used for different purposes.

The distinction is critical for the SC-500 exam:

Azure custom roles control access to Azure resources.

Microsoft Entra custom roles control administrative access to Microsoft Entra resources and capabilities.

Although both systems use concepts such as role definitions, permissions, and role assignments, their permission models and scopes are different. Azure role permissions cannot simply be used in Microsoft Entra custom roles, and Microsoft Entra role permissions cannot be used in Azure custom roles.


1. What Is a Custom Role?

A custom role is a role that an organization creates when the available built-in roles do not provide the appropriate permissions.

The goal is normally to achieve least privilege.

For example, suppose an administrator needs to:

  • View storage accounts
  • Start and stop virtual machines
  • Read certain networking configurations

but should not be able to:

  • Delete resources
  • Assign RBAC roles
  • Modify unrelated resource types

A broad built-in role such as Owner or Contributor might provide excessive permissions.

A custom role can be created containing only the required permissions.

General principle

Use a built-in role when it appropriately meets the requirement. Use a custom role when the built-in roles cannot provide the required permissions with appropriate precision.

This avoids unnecessary custom-role proliferation and reduces administrative complexity.


2. Two Different Custom-Role Systems

For SC-500, keep these two systems clearly separated:

Azure custom roleMicrosoft Entra custom role
Primary purposeManage Azure resourcesManage Microsoft Entra resources
Authorization systemAzure RBACMicrosoft Entra RBAC
Examples of resourcesVMs, storage, networking, databasesUsers, groups, applications, enterprise applications
Permission modelAzure resource-provider operationsMicrosoft Entra resource actions
Assignment scopesAzure management-group, subscription, resource-group/resource scopesDirectory or supported resource-specific scopes
Created/managed throughAzure portal, CLI, PowerShell, REST APIMicrosoft Entra admin center, Microsoft Graph PowerShell/API
Can permissions be mixed?NoNo

The two systems are conceptually similar but technically separate.


3. Azure Custom Roles

Azure custom roles are part of Azure role-based access control (Azure RBAC).

They are used to manage access to Azure resources.

Examples include permissions involving:

  • Virtual machines
  • Storage accounts
  • Azure SQL
  • Virtual networks
  • Key Vault
  • Azure Kubernetes Service
  • Azure Container Registry
  • Other Azure resources

An Azure custom role is a collection of Azure resource permissions.

For example, a custom role might allow a support team to:

  • Read virtual machines
  • Restart virtual machines
  • Read diagnostics

while excluding:

  • Delete virtual machines
  • Modify networking
  • Assign RBAC roles

4. Azure Custom Role Definitions

An Azure role definition describes the permissions available in a role.

A custom role definition can contain properties such as:

  • Name
  • Description
  • Permissions
  • Assignable scopes
  • Role ID

The permissions section can include:

  • Actions
  • NotActions
  • DataActions
  • NotDataActions

These concepts are important for understanding how Azure custom roles are constructed.


5. Actions

Actions specify the Azure control-plane operations that the role can perform.

For example, a custom role might contain permissions that allow the principal to perform operations involving:

  • Reading resources
  • Creating resources
  • Updating resources
  • Deleting resources

The exact permissions are represented using Azure resource-provider operation names.

A permission might look conceptually like:

Microsoft.Compute/virtualMachines/read

This represents a control-plane operation involving virtual machines.


6. NotActions

NotActions specifies control-plane operations that are excluded from the permissions represented by Actions.

For example, a role could broadly allow a set of operations while excluding a particular operation.

However, be careful when interpreting NotActions.

It does not mean:

“Explicitly deny this operation under all circumstances.”

Instead, NotActions subtracts operations from the permissions granted through Actions in that role definition.

A principal might still obtain the excluded permission through another role assignment.

Exam concept

Azure RBAC permissions are additive across role assignments.

Therefore, creating a custom role with NotActions does not guarantee that the principal can never perform the excluded operation.


7. DataActions and NotDataActions

Azure also distinguishes between management-plane operations and operations against data.

DataActions

Specify data-plane operations that the role can perform.

Examples include permissions to:

  • Read blob data
  • Write blob data
  • Read other supported service data

NotDataActions

Exclude specified data-plane operations from the permissions granted through DataActions.

This distinction is especially important for Azure Storage.

For example:

A role that can manage a storage account does not automatically mean that the principal has permission to read the blobs stored in the account.

The custom role may need appropriate data-plane permissions.


8. Example Azure Custom Role

Imagine a help-desk team needs to support Azure virtual machines.

Requirements:

  • View VMs
  • Restart VMs
  • Start VMs
  • Stop VMs
  • Cannot delete VMs
  • Cannot modify networking
  • Cannot assign RBAC roles

A broad Contributor role could provide more permissions than necessary.

Instead, a custom role could be created containing only the required VM operations.

Conceptually:

Support VM Operator

Permissions:

  • VM read
  • VM start
  • VM stop
  • VM restart

Excluded:

  • VM delete
  • RBAC role assignment
  • unrelated resource-management operations

This is a classic least-privilege scenario.


9. Azure Custom Role AssignableScopes

One of the most important properties of an Azure custom role is:

AssignableScopes

This specifies where the custom role definition can be assigned.

A custom role can have assignable scopes at:

  • Management group
  • Subscription
  • Resource group

The role can subsequently be assigned at an appropriate narrower scope within those boundaries, including a resource scope where supported.

For example, a custom role could have:

/subscriptions/00000000-0000-0000-0000-000000000000

as an assignable scope.

The role would then be available for assignment within that subscription and its child scopes.


10. AssignableScopes vs. Assignment Scope

This is an important exam distinction.

AssignableScopes

Determines where the custom role definition is available to be assigned.

Role-assignment scope

Determines where the permissions actually apply to the principal.

For example:

A custom role might have an assignable scope of:

Subscription A

But the role could be assigned to a user at:

Resource Group A

The custom role is available within Subscription A, while the user’s actual permissions apply only to Resource Group A.

Exam rule

AssignableScopes limits where a custom role can be assigned; the role assignment’s scope determines where the assigned permissions apply.


11. Azure Custom Roles and Least Privilege

Custom roles can provide more precise access than broad built-in roles.

Consider three options:

Option 1 — Owner

Very broad permissions, including role assignment.

Option 2 — Contributor

Broad resource-management permissions but no RBAC role-assignment capability.

Option 3 — Custom role

Only the operations required for the user’s job.

If Option 3 satisfies the business requirement, it can provide a stronger least-privilege design.

However, custom roles should not be created simply because customization is possible.

Before creating one:

  1. Identify the exact required operations.
  2. Review existing built-in roles.
  3. Determine whether an existing built-in role is sufficient.
  4. Create a custom role only if necessary.
  5. Limit its permissions.
  6. Limit its assignable scopes.
  7. Assign it at the narrowest practical scope.

12. Who Can Create an Azure Custom Role?

Creating or updating an Azure custom role requires appropriate authorization.

The key Azure permission is:

Microsoft.Authorization/roleDefinitions/write

Among the standard built-in roles, Owner and User Access Administrator include this permission.

This is different from simply assigning an existing role.

Important distinction

A person may have permission to assign an existing role without necessarily having permission to create or modify role definitions.

This distinction can appear in SC-500 scenario questions.


13. Managing Azure Custom Roles

Azure custom roles can be created and managed using:

  • Azure portal
  • Azure CLI
  • Azure PowerShell
  • Azure REST API

For example, administrators can create a custom role through the Azure portal by defining:

  • Role name
  • Description
  • Permissions
  • Assignable scopes

Custom roles are stored in the Microsoft Entra directory associated with the Azure environment and can be shared across subscriptions that trust the same directory.


14. Azure Custom Role Limits

Custom roles should be managed carefully.

Azure supports a maximum of 5,000 custom roles per Microsoft Entra tenant under the standard Azure limit.

This is another reason to avoid creating unnecessary custom roles.

A poorly governed environment could end up with:

  • Duplicate roles
  • Nearly identical roles
  • Roles that are no longer needed
  • Roles containing excessive permissions

A good role-governance process should include periodic review and cleanup.


15. Microsoft Entra Custom Roles

Microsoft Entra ID has its own RBAC system.

Microsoft Entra custom roles are used to provide customized administrative permissions for Microsoft Entra resources and capabilities.

Examples of areas that can be managed through supported Microsoft Entra permissions include:

  • Users
  • Groups
  • Applications
  • Enterprise applications
  • Devices
  • Consent-related operations

Microsoft Entra custom roles are created from a predefined set of permissions that are enabled for custom use.


16. Microsoft Entra Custom Role Permissions

Microsoft Entra custom roles use permissions expressed as Microsoft Entra resource actions.

For example, a custom role could contain permissions such as:

microsoft.directory/applications/basic/update

or:

microsoft.directory/applications/credentials/update

These permissions are different from Azure resource-provider permissions.

Critical exam distinction

Do not confuse:

Microsoft.Compute/...

with:

microsoft.directory/...

The first represents Azure resource-management permissions.

The second represents Microsoft Entra directory permissions.


17. Microsoft Entra Custom Roles Use a Defined Permission Set

You cannot simply create an arbitrary Microsoft Entra permission.

Microsoft Entra custom roles can include permissions that Microsoft makes available for custom use.

This provides granular control while keeping the permission model within supported Microsoft Entra capabilities.

For example, an organization could create a custom role allowing an application-support team to modify selected application properties without granting them broad application-administrator privileges.


18. Example: Microsoft Entra Custom Role

Suppose an organization has an application support team.

The team needs to:

  • Read application registrations
  • Update basic application properties
  • Update application credentials

The team should not receive broad directory administration privileges.

A custom Microsoft Entra role could be created containing only the required application-management permissions.

This is a classic least-privilege scenario.


19. Microsoft Entra Custom Role Scopes

Microsoft Entra custom roles use scopes that differ from Azure RBAC scopes.

Microsoft Entra custom roles can be assigned at:

  • Directory level
  • Supported app-registration resource scope

The exact scope options depend on the Microsoft Entra resource and permission being managed.

Exam warning

Do not automatically apply the Azure RBAC hierarchy:

Management group → subscription → resource group → resource

to Microsoft Entra custom roles.

That hierarchy belongs to Azure resource authorization.


20. Creating Microsoft Entra Custom Roles

Microsoft Entra custom roles can be created using:

  • Microsoft Entra admin center
  • Microsoft Graph PowerShell
  • Microsoft Graph API

In the Microsoft Entra admin center, administrators can navigate to:

Microsoft Entra ID → Roles & admins → New custom role

They then specify:

  • Role name
  • Description
  • Permissions

and create the role.

The role can subsequently be assigned to appropriate users or groups.


21. Microsoft Entra Custom Role Prerequisites

Creating Microsoft Entra custom roles requires appropriate privileged administration permissions.

The current prerequisites include:

  • Microsoft Entra ID P1 or P2
  • Privileged Role Administrator

when creating the role through the documented administrative interfaces.

This is an important distinction from Azure custom-role creation.

Remember

Azure custom role creation

→ Azure authorization permissions such as Microsoft.Authorization/roleDefinitions/write

Microsoft Entra custom role creation

→ Appropriate Microsoft Entra administrative permissions, such as Privileged Role Administrator


22. Microsoft Entra Custom Roles Cannot Use Azure Permissions

Suppose an administrator wants to create a Microsoft Entra custom role.

They cannot add an Azure resource-provider permission such as:

Microsoft.Compute/virtualMachines/read

to the Microsoft Entra custom role.

Likewise, an Azure custom role cannot use a Microsoft Entra permission such as:

microsoft.directory/applications/basic/update

The permission models are separate.

Exam rule

Azure RBAC permissions belong to Azure RBAC roles. Microsoft Entra permissions belong to Microsoft Entra roles.


23. Azure Roles vs. Microsoft Entra Roles

This distinction deserves special attention.

Azure role

Controls access to Azure resources.

Examples:

  • Virtual machines
  • Storage accounts
  • Virtual networks
  • Azure SQL
  • Key Vault

Azure roles are implemented through Azure RBAC.

Microsoft Entra role

Controls administrative access to Microsoft Entra functionality and resources.

Examples:

  • Users
  • Groups
  • Applications
  • Enterprise applications
  • Directory configuration

Microsoft Entra roles are implemented through Microsoft Entra RBAC.

They are separate authorization systems.


24. Application Roles Are Yet Another Concept

SC-500 questions can become confusing because there is another RBAC concept:

Application roles

Application roles are defined by an application and can be used to authorize users or applications within that application.

They are not the same as:

  • Azure RBAC roles
  • Microsoft Entra administrative roles

Therefore:

Application RBAC ≠ Azure RBAC ≠ Microsoft Entra RBAC

Microsoft explicitly distinguishes application-specific RBAC from Azure RBAC and Microsoft Entra RBAC.


25. Role Definition vs. Role Assignment

This concept applies to both Azure RBAC and Microsoft Entra RBAC, although the implementations differ.

Role definition

Defines:

What permissions does the role contain?

Role assignment

Defines:

Who receives the role and at what supported scope?

For Azure RBAC:

Principal + Azure role definition + scope = role assignment

For Microsoft Entra RBAC, a role definition containing Microsoft Entra permissions is assigned to a principal at an applicable directory/resource scope.


26. Assign Custom Roles to Groups When Practical

Custom roles can be assigned to appropriate security principals.

Depending on the authorization system and supported scenario, this can include:

  • Users
  • Groups
  • Service principals
  • Managed identities

For organizational administration, assigning permissions to groups is often preferable to individually assigning the same role to many users.

For example:

Application Support Team

→ Custom Microsoft Entra Application Support role

This simplifies:

  • Access management
  • Auditing
  • Access reviews
  • User onboarding
  • User offboarding

27. Combining Multiple Roles

A user can receive multiple role assignments.

Azure RBAC permissions are effectively additive.

For example, suppose a user has:

Custom VM Operator

and:

Reader

The user’s effective permissions can include permissions from both assignments.

This has an important security consequence.

Creating a custom role with fewer permissions does not necessarily restrict a user if that user already has another role that provides broader permissions.

Example

A custom role excludes:

Microsoft.Compute/virtualMachines/delete

But the same user also has Contributor.

The user could still have VM deletion capability through Contributor.

Exam lesson

Evaluate effective permissions, not just one role definition.


28. Don’t Use NotActions as a Security Deny

This is a common conceptual trap.

Suppose a custom role contains:

Actions: *

and:

NotActions: Microsoft.Compute/virtualMachines/delete

It may appear that the user is explicitly denied the ability to delete VMs.

That’s not necessarily true.

NotActions only removes that operation from the permissions granted by that role definition.

If another role assignment grants VM deletion, the user may still delete VMs.

For an actual deny mechanism, Azure has separate authorization concepts such as deny assignments in supported scenarios.

Exam takeaway

NotActions is not the same as an explicit deny rule.


29. Custom Roles and Least Privilege

The purpose of a custom role should be to make access more precise, not simply to reproduce an overly powerful built-in role under a different name.

A good custom role should:

  • Include only necessary permissions.
  • Avoid unnecessary wildcards.
  • Use narrow assignable scopes where appropriate.
  • Be assigned at the narrowest practical scope.
  • Be assigned only to appropriate principals.
  • Be reviewed periodically.
  • Be removed when no longer required.

30. Be Careful with Wildcards

Azure custom roles support wildcard permissions.

For example:

Microsoft.Storage/*

could provide a large collection of storage-related operations.

Similarly:

*

can provide extremely broad permissions.

Wildcards can make custom roles easier to create but can undermine least privilege.

Best practice

Use specific operations when practical rather than granting a broad wildcard.

For example, if an administrator only needs to restart virtual machines, don’t automatically give that administrator every Compute operation.


31. Privileged Custom Roles

A custom role can itself become a highly privileged role.

For example, a custom Azure role that includes:

Microsoft.Authorization/roleAssignments/write

can grant the ability to create Azure RBAC assignments.

Likewise, permissions to create or modify role definitions are privileged capabilities.

Therefore, custom-role designers must evaluate not only the number of permissions but also the sensitivity of those permissions.

A small role containing a highly privileged authorization operation can be more dangerous than a larger role containing ordinary read operations.


32. Custom Roles and Privileged Identity Management

Microsoft Entra Privileged Identity Management (PIM) can be used with supported privileged role assignments to reduce standing administrative access.

Instead of giving an administrator permanent access, an organization can use an eligible assignment and require activation when the administrator needs to perform privileged work.

Possible controls include:

  • Time-limited activation
  • Approval
  • Multifactor authentication
  • Justification
  • Access reviews

This supports a broader security strategy:

Least privilege + just-in-time access + strong authentication


33. A Practical Process for Creating a Custom Azure Role

Use this process:

Step 1 — Identify the business requirement

Determine exactly what the person or workload needs to accomplish.

Step 2 — Identify the resource types

Determine which Azure resources are involved.

Step 3 — Review built-in roles

Check whether an existing built-in role already satisfies the requirement.

Step 4 — Identify exact operations

Determine the required control-plane and, if applicable, data-plane operations.

Step 5 — Build the custom role

Add only the necessary permissions.

Step 6 — Define assignable scopes

Make the role available only where it needs to be used.

Step 7 — Assign the role

Assign it to the appropriate principal at the narrowest practical scope.

Step 8 — Test effective access

Verify that required operations work and unnecessary permissions are not present.

Step 9 — Review periodically

Remove obsolete roles and permissions.


34. A Practical Process for Creating a Microsoft Entra Custom Role

Use a similar but separate process:

Step 1 — Identify the Microsoft Entra administrative task

For example:

Manage selected application-registration properties.

Step 2 — Review built-in Microsoft Entra roles

Determine whether a built-in role is sufficient.

Step 3 — Identify supported custom-use permissions

Select only the required Microsoft Entra resource actions.

Step 4 — Create the custom role

Define the role name, description, and permissions.

Step 5 — Select the appropriate scope

Use a supported directory or resource-specific scope.

Step 6 — Assign the role

Assign it to the appropriate user or group.

Step 7 — Validate effective permissions

Confirm that the administrator can perform the required operations but does not have unnecessary administrative access.


35. Common SC-500 Exam Traps

Trap 1: Azure custom roles manage Microsoft Entra users

False.

Azure custom roles manage Azure resources.

Microsoft Entra custom roles manage supported Microsoft Entra resources and administrative capabilities.


Trap 2: Microsoft Entra custom roles can contain Azure permissions

False.

The permission models are separate.


Trap 3: Contributor can create custom Azure roles

Generally false.

Contributor does not include the permission required to create or update Azure role definitions.


Trap 4: Owner is required to assign an existing Azure custom role

Not necessarily.

The relevant requirement is permission to create the role assignment. Roles such as Owner, User Access Administrator, and Role Based Access Control Administrator can provide role-assignment capabilities in appropriate scopes.

Creating the custom role definition itself is a separate privilege.


Trap 5: NotActions explicitly denies an operation

False.

It removes operations from the permissions granted by that particular role definition.

Another role assignment could still grant the operation.


Trap 6: AssignableScopes determines where the permissions apply

Not exactly.

AssignableScopes determines where the custom role is available for assignment.

The role assignment scope determines where the permissions actually apply.


Trap 7: Custom roles automatically provide least privilege

False.

A poorly designed custom role can be overly permissive.

Least privilege depends on the permissions selected, scope, and effective role assignments.


Trap 8: A custom role replaces all built-in roles

False.

Built-in roles should generally be preferred when they appropriately satisfy the requirement.


Trap 9: DataActions are the same as Actions

False.

Actions generally represent control-plane operations, while DataActions represent data-plane operations.


Trap 10: Azure RBAC, Microsoft Entra RBAC, and application RBAC are the same

False.

They are separate authorization models serving different purposes.


36. SC-500 Comparison: Azure vs. Microsoft Entra Custom Roles

CharacteristicAzure Custom RoleMicrosoft Entra Custom Role
Authorization systemAzure RBACMicrosoft Entra RBAC
Primary targetAzure resourcesMicrosoft Entra resources/capabilities
Permission formatAzure resource-provider operationsMicrosoft Entra resource actions
Control-plane/data-plane distinctionYes, including Actions/DataActions where supportedDifferent Microsoft Entra permission model
Typical resourcesVM, Storage, SQL, NetworkUsers, groups, applications, enterprise applications
Azure management-group scopeYesNo
Azure subscription scopeYesNo
Azure resource-group scopeYesNo
Microsoft Entra directory scopeNoYes
App registration resource scopeNoSupported
Creation toolsAzure portal, CLI, PowerShell, RESTEntra admin center, Graph PowerShell, Graph API
Typical creation privilegeAzure authorization permission such as roleDefinitions/writePrivileged Role Administrator
Permissions interchangeable?NoNo

37. Exam Scenario Strategy

When a question asks you to design a custom role, work through these questions:

Question 1: What is being secured?

If it is:

  • VM
  • Storage
  • SQL
  • Network
  • Key Vault

think:

Azure RBAC

If it is:

  • User
  • Group
  • Application
  • Enterprise application
  • Directory administration

think:

Microsoft Entra RBAC


Question 2: Is there already a suitable built-in role?

If yes, use the built-in role unless there is a compelling reason not to.

If no, consider a custom role.


Question 3: What exact permissions are required?

Don’t simply choose broad permissions because they are convenient.


Question 4: What is the narrowest scope?

Use the smallest practical scope.


Question 5: Does the role include privileged authorization permissions?

Be particularly careful with permissions that allow:

  • Assigning roles
  • Creating roles
  • Modifying roles
  • Deleting roles
  • Managing other privileged security controls

38. Key Takeaways

For the SC-500 exam, remember:

  1. Azure custom roles are part of Azure RBAC.
  2. Microsoft Entra custom roles are part of Microsoft Entra RBAC.
  3. The two permission models are separate.
  4. Azure custom roles manage Azure resources.
  5. Microsoft Entra custom roles manage supported Microsoft Entra resources and administrative capabilities.
  6. A role definition describes permissions.
  7. A role assignment grants a role to a principal at a scope.
  8. Azure custom roles can contain Actions, NotActions, DataActions, and NotDataActions.
  9. Actions generally represent control-plane operations.
  10. DataActions represent data-plane operations where supported.
  11. NotActions is not an explicit deny mechanism.
  12. Azure custom-role AssignableScopes controls where the role can be assigned.
  13. The role assignment’s scope determines where the assigned permissions apply.
  14. Built-in roles should generally be used when they meet the requirement.
  15. Custom roles are appropriate when built-in roles cannot provide the required level of precision.
  16. Avoid unnecessary wildcard permissions.
  17. Evaluate effective permissions across all role assignments, not just one role.
  18. Privileged role-management permissions require particular caution.
  19. PIM can help reduce standing privileged access.
  20. Azure RBAC ≠ Microsoft Entra RBAC ≠ application RBAC.

Practice Exam Questions

Question 1

An organization needs to create a role that allows support personnel to restart Azure virtual machines but does not allow them to delete VMs or manage networking resources. No existing built-in role provides exactly the required permissions.

What should the security engineer do?

A. Assign Owner at the resource-group scope

B. Create an Azure custom role containing only the required VM permissions

C. Assign Contributor at the VM scope

D. Create a Microsoft Entra custom role

Correct Answer: B. Create an Azure custom role containing only the required VM permissions

Explanation:
The requirement involves Azure virtual machines, so Azure RBAC is the appropriate authorization system. Because the available built-in roles do not provide the required level of precision, an Azure custom role is appropriate. The custom role should contain only the necessary VM operations.


Question 2

An administrator is creating a custom role for Azure resources. The role should be available for assignment within only one subscription.

Which property should the administrator configure?

A. NotActions

B. DataActions

C. AssignableScopes

D. Role assignment name

Correct Answer: C. AssignableScopes

Explanation:
AssignableScopes specifies the scopes where an Azure custom role definition can be assigned. It should not be confused with the scope of an individual role assignment, which determines where the permissions apply to the principal.


Question 3

A user has a custom Azure role containing NotActions that excludes deletion of virtual machines. The user also has the Contributor role at the resource-group scope.

What should the security engineer conclude?

A. The user can never delete virtual machines

B. The custom role overrides Contributor

C. Contributor becomes read-only for the user

D. The user may still be able to delete virtual machines through Contributor

Correct Answer: D. The user may still be able to delete virtual machines through Contributor

Explanation:
NotActions removes an operation from the permissions granted by that particular role definition. It does not create a universal deny. If another role assignment grants the permission, the user can still receive it through that other role.


Question 4

An organization needs to create a custom role that allows an application-support team to update selected properties of Microsoft Entra application registrations. The team should not receive broad directory-administrator permissions.

Which solution should be used?

A. Microsoft Entra custom role

B. Azure Contributor role

C. Azure custom role

D. Azure Owner role

Correct Answer: A. Microsoft Entra custom role

Explanation:
Application registrations are Microsoft Entra resources. A Microsoft Entra custom role can contain the specific supported Microsoft Entra permissions required for the application-support scenario without granting broad directory administration.


Question 5

Which statement correctly distinguishes Azure custom roles from Microsoft Entra custom roles?

A. Azure custom roles manage Microsoft Entra users, while Microsoft Entra custom roles manage virtual machines

B. Azure custom roles and Microsoft Entra custom roles use exactly the same permission model

C. Azure custom roles manage Azure resources, while Microsoft Entra custom roles manage supported Microsoft Entra resources and administrative capabilities

D. Microsoft Entra custom roles can contain Azure resource-provider permissions

Correct Answer: C. Azure custom roles manage Azure resources, while Microsoft Entra custom roles manage supported Microsoft Entra resources and administrative capabilities

Explanation:
Azure RBAC and Microsoft Entra RBAC are separate authorization systems. Azure custom roles are used for Azure resources, while Microsoft Entra custom roles are used for supported Microsoft Entra administration scenarios.


Question 6

An Azure custom role needs to allow a service principal to read blob data from a storage account. Which type of permission is relevant to granting access to the actual blob data?

A. NotActions

B. DataActions

C. AssignableScopes

D. RoleDefinitions/write

Correct Answer: B. DataActions

Explanation:
DataActions represent data-plane operations for supported Azure services. Reading blob data is a data-plane operation and therefore requires an appropriate data-access permission rather than merely a management-plane Action.


Question 7

A security engineer wants to create an Azure custom role. Which Azure permission is directly associated with creating or updating an Azure custom role definition?

A. Microsoft.Authorization/roleDefinitions/write

B. Microsoft.Compute/virtualMachines/read

C. Microsoft.Authorization/roleAssignments/read

D. Microsoft.Storage/storageAccounts/read

Correct Answer: A. Microsoft.Authorization/roleDefinitions/write

Explanation:
Microsoft.Authorization/roleDefinitions/write is the authorization permission associated with creating or updating Azure role definitions. This is distinct from assigning an already existing role to a principal.


Question 8

A security administrator needs to create a Microsoft Entra custom role through the Microsoft Entra administrative experience.

Which role is associated with the required administrative privilege for creating the custom role?

A. Global Reader

B. Security Reader

C. Privileged Role Administrator

D. Azure Contributor

Correct Answer: C. Privileged Role Administrator

Explanation:
Creating Microsoft Entra custom roles requires appropriate Microsoft Entra administrative privileges. The documented prerequisite includes the Privileged Role Administrator role, along with the appropriate Microsoft Entra licensing.


Question 9

An Azure administrator creates a custom role with the following design:

  • Read virtual machines
  • Start virtual machines
  • Stop virtual machines
  • Delete virtual machines

The administrator assigns the role to a support group that only needs to start and stop VMs.

What should the security engineer recommend?

A. Keep the role because custom roles should contain broad permissions

B. Replace the role with Owner

C. Add more permissions so the role is easier to reuse

D. Remove the unnecessary delete permission to better follow least privilege

Correct Answer: D. Remove the unnecessary delete permission to better follow least privilege

Explanation:
The group does not need VM deletion capability. A custom role should contain only the permissions required for the business task. Removing unnecessary privileged operations reduces the potential impact of account compromise or misuse.


Question 10

A security engineer is deciding whether to create a custom Azure role or a custom Microsoft Entra role. The requirement is to allow administrators to manage selected users and groups in Microsoft Entra ID.

Which solution is appropriate?

A. Azure custom role

B. Microsoft Entra custom role

C. Azure Storage Blob Data Reader

D. Azure Contributor

Correct Answer: B. Microsoft Entra custom role

Explanation:
The requirement concerns management of Microsoft Entra users and groups rather than Azure resources. Therefore, the appropriate authorization system is Microsoft Entra RBAC, and a Microsoft Entra custom role should be considered if an existing built-in role does not provide the required permissions.


One particularly important distinction to memorize for this section is:

Azure custom role → Azure resources → Azure RBAC

Microsoft Entra custom role → Microsoft Entra resources/administration → Microsoft Entra RBAC

And for Azure custom roles, remember the three concepts that are easy to confuse on the exam: Actions/DataActions define permissions, AssignableScopes controls where the custom role can be assigned, and the role-assignment scope controls where the granted permissions actually apply.


Go to the SC-500 Exam Prep Hub main page

Leave a Reply