This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage identity, access, and governance (20–25%)
--> Implement governance to enforce security and regulatory compliance
--> Manage custom roles, including Azure roles and Microsoft Entra roles
Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.
Overview
Role-based access control (RBAC) is a fundamental component of cloud security. Rather than granting users unrestricted administrative privileges, RBAC allows an organization to assign only the permissions required to perform a particular job.
Azure and Microsoft Entra ID both support custom roles, but they are used for different purposes.
The distinction is critical for the SC-500 exam:
Azure custom roles control access to Azure resources.
Microsoft Entra custom roles control administrative access to Microsoft Entra resources and capabilities.
Although both systems use concepts such as role definitions, permissions, and role assignments, their permission models and scopes are different. Azure role permissions cannot simply be used in Microsoft Entra custom roles, and Microsoft Entra role permissions cannot be used in Azure custom roles.
1. What Is a Custom Role?
A custom role is a role that an organization creates when the available built-in roles do not provide the appropriate permissions.
The goal is normally to achieve least privilege.
For example, suppose an administrator needs to:
- View storage accounts
- Start and stop virtual machines
- Read certain networking configurations
but should not be able to:
- Delete resources
- Assign RBAC roles
- Modify unrelated resource types
A broad built-in role such as Owner or Contributor might provide excessive permissions.
A custom role can be created containing only the required permissions.
General principle
Use a built-in role when it appropriately meets the requirement. Use a custom role when the built-in roles cannot provide the required permissions with appropriate precision.
This avoids unnecessary custom-role proliferation and reduces administrative complexity.
2. Two Different Custom-Role Systems
For SC-500, keep these two systems clearly separated:
| Azure custom role | Microsoft Entra custom role | |
|---|---|---|
| Primary purpose | Manage Azure resources | Manage Microsoft Entra resources |
| Authorization system | Azure RBAC | Microsoft Entra RBAC |
| Examples of resources | VMs, storage, networking, databases | Users, groups, applications, enterprise applications |
| Permission model | Azure resource-provider operations | Microsoft Entra resource actions |
| Assignment scopes | Azure management-group, subscription, resource-group/resource scopes | Directory or supported resource-specific scopes |
| Created/managed through | Azure portal, CLI, PowerShell, REST API | Microsoft Entra admin center, Microsoft Graph PowerShell/API |
| Can permissions be mixed? | No | No |
The two systems are conceptually similar but technically separate.
3. Azure Custom Roles
Azure custom roles are part of Azure role-based access control (Azure RBAC).
They are used to manage access to Azure resources.
Examples include permissions involving:
- Virtual machines
- Storage accounts
- Azure SQL
- Virtual networks
- Key Vault
- Azure Kubernetes Service
- Azure Container Registry
- Other Azure resources
An Azure custom role is a collection of Azure resource permissions.
For example, a custom role might allow a support team to:
- Read virtual machines
- Restart virtual machines
- Read diagnostics
while excluding:
- Delete virtual machines
- Modify networking
- Assign RBAC roles
4. Azure Custom Role Definitions
An Azure role definition describes the permissions available in a role.
A custom role definition can contain properties such as:
- Name
- Description
- Permissions
- Assignable scopes
- Role ID
The permissions section can include:
ActionsNotActionsDataActionsNotDataActions
These concepts are important for understanding how Azure custom roles are constructed.
5. Actions
Actions specify the Azure control-plane operations that the role can perform.
For example, a custom role might contain permissions that allow the principal to perform operations involving:
- Reading resources
- Creating resources
- Updating resources
- Deleting resources
The exact permissions are represented using Azure resource-provider operation names.
A permission might look conceptually like:
Microsoft.Compute/virtualMachines/read
This represents a control-plane operation involving virtual machines.
6. NotActions
NotActions specifies control-plane operations that are excluded from the permissions represented by Actions.
For example, a role could broadly allow a set of operations while excluding a particular operation.
However, be careful when interpreting NotActions.
It does not mean:
“Explicitly deny this operation under all circumstances.”
Instead, NotActions subtracts operations from the permissions granted through Actions in that role definition.
A principal might still obtain the excluded permission through another role assignment.
Exam concept
Azure RBAC permissions are additive across role assignments.
Therefore, creating a custom role with NotActions does not guarantee that the principal can never perform the excluded operation.
7. DataActions and NotDataActions
Azure also distinguishes between management-plane operations and operations against data.
DataActions
Specify data-plane operations that the role can perform.
Examples include permissions to:
- Read blob data
- Write blob data
- Read other supported service data
NotDataActions
Exclude specified data-plane operations from the permissions granted through DataActions.
This distinction is especially important for Azure Storage.
For example:
A role that can manage a storage account does not automatically mean that the principal has permission to read the blobs stored in the account.
The custom role may need appropriate data-plane permissions.
8. Example Azure Custom Role
Imagine a help-desk team needs to support Azure virtual machines.
Requirements:
- View VMs
- Restart VMs
- Start VMs
- Stop VMs
- Cannot delete VMs
- Cannot modify networking
- Cannot assign RBAC roles
A broad Contributor role could provide more permissions than necessary.
Instead, a custom role could be created containing only the required VM operations.
Conceptually:
Support VM Operator
Permissions:
- VM read
- VM start
- VM stop
- VM restart
Excluded:
- VM delete
- RBAC role assignment
- unrelated resource-management operations
This is a classic least-privilege scenario.
9. Azure Custom Role AssignableScopes
One of the most important properties of an Azure custom role is:
AssignableScopes
This specifies where the custom role definition can be assigned.
A custom role can have assignable scopes at:
- Management group
- Subscription
- Resource group
The role can subsequently be assigned at an appropriate narrower scope within those boundaries, including a resource scope where supported.
For example, a custom role could have:
/subscriptions/00000000-0000-0000-0000-000000000000
as an assignable scope.
The role would then be available for assignment within that subscription and its child scopes.
10. AssignableScopes vs. Assignment Scope
This is an important exam distinction.
AssignableScopes
Determines where the custom role definition is available to be assigned.
Role-assignment scope
Determines where the permissions actually apply to the principal.
For example:
A custom role might have an assignable scope of:
Subscription A
But the role could be assigned to a user at:
Resource Group A
The custom role is available within Subscription A, while the user’s actual permissions apply only to Resource Group A.
Exam rule
AssignableScopes limits where a custom role can be assigned; the role assignment’s scope determines where the assigned permissions apply.
11. Azure Custom Roles and Least Privilege
Custom roles can provide more precise access than broad built-in roles.
Consider three options:
Option 1 — Owner
Very broad permissions, including role assignment.
Option 2 — Contributor
Broad resource-management permissions but no RBAC role-assignment capability.
Option 3 — Custom role
Only the operations required for the user’s job.
If Option 3 satisfies the business requirement, it can provide a stronger least-privilege design.
However, custom roles should not be created simply because customization is possible.
Before creating one:
- Identify the exact required operations.
- Review existing built-in roles.
- Determine whether an existing built-in role is sufficient.
- Create a custom role only if necessary.
- Limit its permissions.
- Limit its assignable scopes.
- Assign it at the narrowest practical scope.
12. Who Can Create an Azure Custom Role?
Creating or updating an Azure custom role requires appropriate authorization.
The key Azure permission is:
Microsoft.Authorization/roleDefinitions/write
Among the standard built-in roles, Owner and User Access Administrator include this permission.
This is different from simply assigning an existing role.
Important distinction
A person may have permission to assign an existing role without necessarily having permission to create or modify role definitions.
This distinction can appear in SC-500 scenario questions.
13. Managing Azure Custom Roles
Azure custom roles can be created and managed using:
- Azure portal
- Azure CLI
- Azure PowerShell
- Azure REST API
For example, administrators can create a custom role through the Azure portal by defining:
- Role name
- Description
- Permissions
- Assignable scopes
Custom roles are stored in the Microsoft Entra directory associated with the Azure environment and can be shared across subscriptions that trust the same directory.
14. Azure Custom Role Limits
Custom roles should be managed carefully.
Azure supports a maximum of 5,000 custom roles per Microsoft Entra tenant under the standard Azure limit.
This is another reason to avoid creating unnecessary custom roles.
A poorly governed environment could end up with:
- Duplicate roles
- Nearly identical roles
- Roles that are no longer needed
- Roles containing excessive permissions
A good role-governance process should include periodic review and cleanup.
15. Microsoft Entra Custom Roles
Microsoft Entra ID has its own RBAC system.
Microsoft Entra custom roles are used to provide customized administrative permissions for Microsoft Entra resources and capabilities.
Examples of areas that can be managed through supported Microsoft Entra permissions include:
- Users
- Groups
- Applications
- Enterprise applications
- Devices
- Consent-related operations
Microsoft Entra custom roles are created from a predefined set of permissions that are enabled for custom use.
16. Microsoft Entra Custom Role Permissions
Microsoft Entra custom roles use permissions expressed as Microsoft Entra resource actions.
For example, a custom role could contain permissions such as:
microsoft.directory/applications/basic/update
or:
microsoft.directory/applications/credentials/update
These permissions are different from Azure resource-provider permissions.
Critical exam distinction
Do not confuse:
Microsoft.Compute/...
with:
microsoft.directory/...
The first represents Azure resource-management permissions.
The second represents Microsoft Entra directory permissions.
17. Microsoft Entra Custom Roles Use a Defined Permission Set
You cannot simply create an arbitrary Microsoft Entra permission.
Microsoft Entra custom roles can include permissions that Microsoft makes available for custom use.
This provides granular control while keeping the permission model within supported Microsoft Entra capabilities.
For example, an organization could create a custom role allowing an application-support team to modify selected application properties without granting them broad application-administrator privileges.
18. Example: Microsoft Entra Custom Role
Suppose an organization has an application support team.
The team needs to:
- Read application registrations
- Update basic application properties
- Update application credentials
The team should not receive broad directory administration privileges.
A custom Microsoft Entra role could be created containing only the required application-management permissions.
This is a classic least-privilege scenario.
19. Microsoft Entra Custom Role Scopes
Microsoft Entra custom roles use scopes that differ from Azure RBAC scopes.
Microsoft Entra custom roles can be assigned at:
- Directory level
- Supported app-registration resource scope
The exact scope options depend on the Microsoft Entra resource and permission being managed.
Exam warning
Do not automatically apply the Azure RBAC hierarchy:
Management group → subscription → resource group → resource
to Microsoft Entra custom roles.
That hierarchy belongs to Azure resource authorization.
20. Creating Microsoft Entra Custom Roles
Microsoft Entra custom roles can be created using:
- Microsoft Entra admin center
- Microsoft Graph PowerShell
- Microsoft Graph API
In the Microsoft Entra admin center, administrators can navigate to:
Microsoft Entra ID → Roles & admins → New custom role
They then specify:
- Role name
- Description
- Permissions
and create the role.
The role can subsequently be assigned to appropriate users or groups.
21. Microsoft Entra Custom Role Prerequisites
Creating Microsoft Entra custom roles requires appropriate privileged administration permissions.
The current prerequisites include:
- Microsoft Entra ID P1 or P2
- Privileged Role Administrator
when creating the role through the documented administrative interfaces.
This is an important distinction from Azure custom-role creation.
Remember
Azure custom role creation
→ Azure authorization permissions such as Microsoft.Authorization/roleDefinitions/write
Microsoft Entra custom role creation
→ Appropriate Microsoft Entra administrative permissions, such as Privileged Role Administrator
22. Microsoft Entra Custom Roles Cannot Use Azure Permissions
Suppose an administrator wants to create a Microsoft Entra custom role.
They cannot add an Azure resource-provider permission such as:
Microsoft.Compute/virtualMachines/read
to the Microsoft Entra custom role.
Likewise, an Azure custom role cannot use a Microsoft Entra permission such as:
microsoft.directory/applications/basic/update
The permission models are separate.
Exam rule
Azure RBAC permissions belong to Azure RBAC roles. Microsoft Entra permissions belong to Microsoft Entra roles.
23. Azure Roles vs. Microsoft Entra Roles
This distinction deserves special attention.
Azure role
Controls access to Azure resources.
Examples:
- Virtual machines
- Storage accounts
- Virtual networks
- Azure SQL
- Key Vault
Azure roles are implemented through Azure RBAC.
Microsoft Entra role
Controls administrative access to Microsoft Entra functionality and resources.
Examples:
- Users
- Groups
- Applications
- Enterprise applications
- Directory configuration
Microsoft Entra roles are implemented through Microsoft Entra RBAC.
They are separate authorization systems.
24. Application Roles Are Yet Another Concept
SC-500 questions can become confusing because there is another RBAC concept:
Application roles
Application roles are defined by an application and can be used to authorize users or applications within that application.
They are not the same as:
- Azure RBAC roles
- Microsoft Entra administrative roles
Therefore:
Application RBAC ≠ Azure RBAC ≠ Microsoft Entra RBAC
Microsoft explicitly distinguishes application-specific RBAC from Azure RBAC and Microsoft Entra RBAC.
25. Role Definition vs. Role Assignment
This concept applies to both Azure RBAC and Microsoft Entra RBAC, although the implementations differ.
Role definition
Defines:
What permissions does the role contain?
Role assignment
Defines:
Who receives the role and at what supported scope?
For Azure RBAC:
Principal + Azure role definition + scope = role assignment
For Microsoft Entra RBAC, a role definition containing Microsoft Entra permissions is assigned to a principal at an applicable directory/resource scope.
26. Assign Custom Roles to Groups When Practical
Custom roles can be assigned to appropriate security principals.
Depending on the authorization system and supported scenario, this can include:
- Users
- Groups
- Service principals
- Managed identities
For organizational administration, assigning permissions to groups is often preferable to individually assigning the same role to many users.
For example:
Application Support Team
→ Custom Microsoft Entra Application Support role
This simplifies:
- Access management
- Auditing
- Access reviews
- User onboarding
- User offboarding
27. Combining Multiple Roles
A user can receive multiple role assignments.
Azure RBAC permissions are effectively additive.
For example, suppose a user has:
Custom VM Operator
and:
Reader
The user’s effective permissions can include permissions from both assignments.
This has an important security consequence.
Creating a custom role with fewer permissions does not necessarily restrict a user if that user already has another role that provides broader permissions.
Example
A custom role excludes:
Microsoft.Compute/virtualMachines/delete
But the same user also has Contributor.
The user could still have VM deletion capability through Contributor.
Exam lesson
Evaluate effective permissions, not just one role definition.
28. Don’t Use NotActions as a Security Deny
This is a common conceptual trap.
Suppose a custom role contains:
Actions: *
and:
NotActions: Microsoft.Compute/virtualMachines/delete
It may appear that the user is explicitly denied the ability to delete VMs.
That’s not necessarily true.
NotActions only removes that operation from the permissions granted by that role definition.
If another role assignment grants VM deletion, the user may still delete VMs.
For an actual deny mechanism, Azure has separate authorization concepts such as deny assignments in supported scenarios.
Exam takeaway
NotActions is not the same as an explicit deny rule.
29. Custom Roles and Least Privilege
The purpose of a custom role should be to make access more precise, not simply to reproduce an overly powerful built-in role under a different name.
A good custom role should:
- Include only necessary permissions.
- Avoid unnecessary wildcards.
- Use narrow assignable scopes where appropriate.
- Be assigned at the narrowest practical scope.
- Be assigned only to appropriate principals.
- Be reviewed periodically.
- Be removed when no longer required.
30. Be Careful with Wildcards
Azure custom roles support wildcard permissions.
For example:
Microsoft.Storage/*
could provide a large collection of storage-related operations.
Similarly:
*
can provide extremely broad permissions.
Wildcards can make custom roles easier to create but can undermine least privilege.
Best practice
Use specific operations when practical rather than granting a broad wildcard.
For example, if an administrator only needs to restart virtual machines, don’t automatically give that administrator every Compute operation.
31. Privileged Custom Roles
A custom role can itself become a highly privileged role.
For example, a custom Azure role that includes:
Microsoft.Authorization/roleAssignments/write
can grant the ability to create Azure RBAC assignments.
Likewise, permissions to create or modify role definitions are privileged capabilities.
Therefore, custom-role designers must evaluate not only the number of permissions but also the sensitivity of those permissions.
A small role containing a highly privileged authorization operation can be more dangerous than a larger role containing ordinary read operations.
32. Custom Roles and Privileged Identity Management
Microsoft Entra Privileged Identity Management (PIM) can be used with supported privileged role assignments to reduce standing administrative access.
Instead of giving an administrator permanent access, an organization can use an eligible assignment and require activation when the administrator needs to perform privileged work.
Possible controls include:
- Time-limited activation
- Approval
- Multifactor authentication
- Justification
- Access reviews
This supports a broader security strategy:
Least privilege + just-in-time access + strong authentication
33. A Practical Process for Creating a Custom Azure Role
Use this process:
Step 1 — Identify the business requirement
Determine exactly what the person or workload needs to accomplish.
Step 2 — Identify the resource types
Determine which Azure resources are involved.
Step 3 — Review built-in roles
Check whether an existing built-in role already satisfies the requirement.
Step 4 — Identify exact operations
Determine the required control-plane and, if applicable, data-plane operations.
Step 5 — Build the custom role
Add only the necessary permissions.
Step 6 — Define assignable scopes
Make the role available only where it needs to be used.
Step 7 — Assign the role
Assign it to the appropriate principal at the narrowest practical scope.
Step 8 — Test effective access
Verify that required operations work and unnecessary permissions are not present.
Step 9 — Review periodically
Remove obsolete roles and permissions.
34. A Practical Process for Creating a Microsoft Entra Custom Role
Use a similar but separate process:
Step 1 — Identify the Microsoft Entra administrative task
For example:
Manage selected application-registration properties.
Step 2 — Review built-in Microsoft Entra roles
Determine whether a built-in role is sufficient.
Step 3 — Identify supported custom-use permissions
Select only the required Microsoft Entra resource actions.
Step 4 — Create the custom role
Define the role name, description, and permissions.
Step 5 — Select the appropriate scope
Use a supported directory or resource-specific scope.
Step 6 — Assign the role
Assign it to the appropriate user or group.
Step 7 — Validate effective permissions
Confirm that the administrator can perform the required operations but does not have unnecessary administrative access.
35. Common SC-500 Exam Traps
Trap 1: Azure custom roles manage Microsoft Entra users
False.
Azure custom roles manage Azure resources.
Microsoft Entra custom roles manage supported Microsoft Entra resources and administrative capabilities.
Trap 2: Microsoft Entra custom roles can contain Azure permissions
False.
The permission models are separate.
Trap 3: Contributor can create custom Azure roles
Generally false.
Contributor does not include the permission required to create or update Azure role definitions.
Trap 4: Owner is required to assign an existing Azure custom role
Not necessarily.
The relevant requirement is permission to create the role assignment. Roles such as Owner, User Access Administrator, and Role Based Access Control Administrator can provide role-assignment capabilities in appropriate scopes.
Creating the custom role definition itself is a separate privilege.
Trap 5: NotActions explicitly denies an operation
False.
It removes operations from the permissions granted by that particular role definition.
Another role assignment could still grant the operation.
Trap 6: AssignableScopes determines where the permissions apply
Not exactly.
AssignableScopes determines where the custom role is available for assignment.
The role assignment scope determines where the permissions actually apply.
Trap 7: Custom roles automatically provide least privilege
False.
A poorly designed custom role can be overly permissive.
Least privilege depends on the permissions selected, scope, and effective role assignments.
Trap 8: A custom role replaces all built-in roles
False.
Built-in roles should generally be preferred when they appropriately satisfy the requirement.
Trap 9: DataActions are the same as Actions
False.
Actions generally represent control-plane operations, while DataActions represent data-plane operations.
Trap 10: Azure RBAC, Microsoft Entra RBAC, and application RBAC are the same
False.
They are separate authorization models serving different purposes.
36. SC-500 Comparison: Azure vs. Microsoft Entra Custom Roles
| Characteristic | Azure Custom Role | Microsoft Entra Custom Role |
|---|---|---|
| Authorization system | Azure RBAC | Microsoft Entra RBAC |
| Primary target | Azure resources | Microsoft Entra resources/capabilities |
| Permission format | Azure resource-provider operations | Microsoft Entra resource actions |
| Control-plane/data-plane distinction | Yes, including Actions/DataActions where supported | Different Microsoft Entra permission model |
| Typical resources | VM, Storage, SQL, Network | Users, groups, applications, enterprise applications |
| Azure management-group scope | Yes | No |
| Azure subscription scope | Yes | No |
| Azure resource-group scope | Yes | No |
| Microsoft Entra directory scope | No | Yes |
| App registration resource scope | No | Supported |
| Creation tools | Azure portal, CLI, PowerShell, REST | Entra admin center, Graph PowerShell, Graph API |
| Typical creation privilege | Azure authorization permission such as roleDefinitions/write | Privileged Role Administrator |
| Permissions interchangeable? | No | No |
37. Exam Scenario Strategy
When a question asks you to design a custom role, work through these questions:
Question 1: What is being secured?
If it is:
- VM
- Storage
- SQL
- Network
- Key Vault
think:
Azure RBAC
If it is:
- User
- Group
- Application
- Enterprise application
- Directory administration
think:
Microsoft Entra RBAC
Question 2: Is there already a suitable built-in role?
If yes, use the built-in role unless there is a compelling reason not to.
If no, consider a custom role.
Question 3: What exact permissions are required?
Don’t simply choose broad permissions because they are convenient.
Question 4: What is the narrowest scope?
Use the smallest practical scope.
Question 5: Does the role include privileged authorization permissions?
Be particularly careful with permissions that allow:
- Assigning roles
- Creating roles
- Modifying roles
- Deleting roles
- Managing other privileged security controls
38. Key Takeaways
For the SC-500 exam, remember:
- Azure custom roles are part of Azure RBAC.
- Microsoft Entra custom roles are part of Microsoft Entra RBAC.
- The two permission models are separate.
- Azure custom roles manage Azure resources.
- Microsoft Entra custom roles manage supported Microsoft Entra resources and administrative capabilities.
- A role definition describes permissions.
- A role assignment grants a role to a principal at a scope.
- Azure custom roles can contain
Actions,NotActions,DataActions, andNotDataActions. Actionsgenerally represent control-plane operations.DataActionsrepresent data-plane operations where supported.NotActionsis not an explicit deny mechanism.- Azure custom-role
AssignableScopescontrols where the role can be assigned. - The role assignment’s scope determines where the assigned permissions apply.
- Built-in roles should generally be used when they meet the requirement.
- Custom roles are appropriate when built-in roles cannot provide the required level of precision.
- Avoid unnecessary wildcard permissions.
- Evaluate effective permissions across all role assignments, not just one role.
- Privileged role-management permissions require particular caution.
- PIM can help reduce standing privileged access.
- Azure RBAC ≠ Microsoft Entra RBAC ≠ application RBAC.
Practice Exam Questions
Question 1
An organization needs to create a role that allows support personnel to restart Azure virtual machines but does not allow them to delete VMs or manage networking resources. No existing built-in role provides exactly the required permissions.
What should the security engineer do?
A. Assign Owner at the resource-group scope
B. Create an Azure custom role containing only the required VM permissions
C. Assign Contributor at the VM scope
D. Create a Microsoft Entra custom role
Correct Answer: B. Create an Azure custom role containing only the required VM permissions
Explanation:
The requirement involves Azure virtual machines, so Azure RBAC is the appropriate authorization system. Because the available built-in roles do not provide the required level of precision, an Azure custom role is appropriate. The custom role should contain only the necessary VM operations.
Question 2
An administrator is creating a custom role for Azure resources. The role should be available for assignment within only one subscription.
Which property should the administrator configure?
A. NotActions
B. DataActions
C. AssignableScopes
D. Role assignment name
Correct Answer: C. AssignableScopes
Explanation:AssignableScopes specifies the scopes where an Azure custom role definition can be assigned. It should not be confused with the scope of an individual role assignment, which determines where the permissions apply to the principal.
Question 3
A user has a custom Azure role containing NotActions that excludes deletion of virtual machines. The user also has the Contributor role at the resource-group scope.
What should the security engineer conclude?
A. The user can never delete virtual machines
B. The custom role overrides Contributor
C. Contributor becomes read-only for the user
D. The user may still be able to delete virtual machines through Contributor
Correct Answer: D. The user may still be able to delete virtual machines through Contributor
Explanation:NotActions removes an operation from the permissions granted by that particular role definition. It does not create a universal deny. If another role assignment grants the permission, the user can still receive it through that other role.
Question 4
An organization needs to create a custom role that allows an application-support team to update selected properties of Microsoft Entra application registrations. The team should not receive broad directory-administrator permissions.
Which solution should be used?
A. Microsoft Entra custom role
B. Azure Contributor role
C. Azure custom role
D. Azure Owner role
Correct Answer: A. Microsoft Entra custom role
Explanation:
Application registrations are Microsoft Entra resources. A Microsoft Entra custom role can contain the specific supported Microsoft Entra permissions required for the application-support scenario without granting broad directory administration.
Question 5
Which statement correctly distinguishes Azure custom roles from Microsoft Entra custom roles?
A. Azure custom roles manage Microsoft Entra users, while Microsoft Entra custom roles manage virtual machines
B. Azure custom roles and Microsoft Entra custom roles use exactly the same permission model
C. Azure custom roles manage Azure resources, while Microsoft Entra custom roles manage supported Microsoft Entra resources and administrative capabilities
D. Microsoft Entra custom roles can contain Azure resource-provider permissions
Correct Answer: C. Azure custom roles manage Azure resources, while Microsoft Entra custom roles manage supported Microsoft Entra resources and administrative capabilities
Explanation:
Azure RBAC and Microsoft Entra RBAC are separate authorization systems. Azure custom roles are used for Azure resources, while Microsoft Entra custom roles are used for supported Microsoft Entra administration scenarios.
Question 6
An Azure custom role needs to allow a service principal to read blob data from a storage account. Which type of permission is relevant to granting access to the actual blob data?
A. NotActions
B. DataActions
C. AssignableScopes
D. RoleDefinitions/write
Correct Answer: B. DataActions
Explanation:DataActions represent data-plane operations for supported Azure services. Reading blob data is a data-plane operation and therefore requires an appropriate data-access permission rather than merely a management-plane Action.
Question 7
A security engineer wants to create an Azure custom role. Which Azure permission is directly associated with creating or updating an Azure custom role definition?
A. Microsoft.Authorization/roleDefinitions/write
B. Microsoft.Compute/virtualMachines/read
C. Microsoft.Authorization/roleAssignments/read
D. Microsoft.Storage/storageAccounts/read
Correct Answer: A. Microsoft.Authorization/roleDefinitions/write
Explanation:Microsoft.Authorization/roleDefinitions/write is the authorization permission associated with creating or updating Azure role definitions. This is distinct from assigning an already existing role to a principal.
Question 8
A security administrator needs to create a Microsoft Entra custom role through the Microsoft Entra administrative experience.
Which role is associated with the required administrative privilege for creating the custom role?
A. Global Reader
B. Security Reader
C. Privileged Role Administrator
D. Azure Contributor
Correct Answer: C. Privileged Role Administrator
Explanation:
Creating Microsoft Entra custom roles requires appropriate Microsoft Entra administrative privileges. The documented prerequisite includes the Privileged Role Administrator role, along with the appropriate Microsoft Entra licensing.
Question 9
An Azure administrator creates a custom role with the following design:
- Read virtual machines
- Start virtual machines
- Stop virtual machines
- Delete virtual machines
The administrator assigns the role to a support group that only needs to start and stop VMs.
What should the security engineer recommend?
A. Keep the role because custom roles should contain broad permissions
B. Replace the role with Owner
C. Add more permissions so the role is easier to reuse
D. Remove the unnecessary delete permission to better follow least privilege
Correct Answer: D. Remove the unnecessary delete permission to better follow least privilege
Explanation:
The group does not need VM deletion capability. A custom role should contain only the permissions required for the business task. Removing unnecessary privileged operations reduces the potential impact of account compromise or misuse.
Question 10
A security engineer is deciding whether to create a custom Azure role or a custom Microsoft Entra role. The requirement is to allow administrators to manage selected users and groups in Microsoft Entra ID.
Which solution is appropriate?
A. Azure custom role
B. Microsoft Entra custom role
C. Azure Storage Blob Data Reader
D. Azure Contributor
Correct Answer: B. Microsoft Entra custom role
Explanation:
The requirement concerns management of Microsoft Entra users and groups rather than Azure resources. Therefore, the appropriate authorization system is Microsoft Entra RBAC, and a Microsoft Entra custom role should be considered if an existing built-in role does not provide the required permissions.
One particularly important distinction to memorize for this section is:
Azure custom role → Azure resources → Azure RBAC
Microsoft Entra custom role → Microsoft Entra resources/administration → Microsoft Entra RBAC
And for Azure custom roles, remember the three concepts that are easy to confuse on the exam: Actions/DataActions define permissions, AssignableScopes controls where the custom role can be assigned, and the role-assignment scope controls where the granted permissions actually apply.
Go to the SC-500 Exam Prep Hub main page
