🔒 Guided

Pre-launch preview. Authorised access only.

Incorrect code

Guided by A Guide to Cloud
Explore AB-900 AI-901
Guided SC-900 Domain 2
Domain 2 — Module 6 of 8 75%
10 of 28 overall

SC-900 Study Guide

Domain 1: Security, Compliance & Identity Concepts

  • Security Foundations: Shared Responsibility & Defence-in-Depth Free
  • Zero Trust: Never Trust, Always Verify Free
  • Encryption, Hashing & GRC Free
  • Identity: The New Security Perimeter Free

Domain 2: Microsoft Entra Capabilities

  • Microsoft Entra ID: Your Identity Hub Free
  • Hybrid & External Identities
  • Authentication: Passwords, MFA & Passwordless
  • Password Protection & Self-Service Reset
  • Conditional Access: Smart Access Decisions
  • Entra Roles and RBAC
  • Identity Governance: Entitlements and Access Reviews
  • PIM and Identity Protection

Domain 3: Microsoft Security Solutions

  • Azure Network Defence: DDoS, Firewall & WAF
  • Azure Infrastructure Security: VNets, NSGs, Bastion & Key Vault
  • Microsoft Defender for Cloud
  • Microsoft Sentinel: SIEM Meets SOAR
  • Defender XDR: The Unified Threat Platform
  • Microsoft Defender for Office 365
  • Microsoft Defender for Endpoint
  • Defender for Cloud Apps & Defender for Identity
  • Vulnerability Management & Threat Intelligence

Domain 4: Microsoft Compliance Solutions

  • Service Trust Portal, Privacy Principles & Microsoft Priva
  • The Purview Portal & Compliance Manager
  • Data Classification & Sensitivity Labels
  • Data Loss Prevention (DLP)
  • Records Management & Retention
  • Insider Risk Management
  • eDiscovery & Audit

SC-900 Study Guide

Domain 1: Security, Compliance & Identity Concepts

  • Security Foundations: Shared Responsibility & Defence-in-Depth Free
  • Zero Trust: Never Trust, Always Verify Free
  • Encryption, Hashing & GRC Free
  • Identity: The New Security Perimeter Free

Domain 2: Microsoft Entra Capabilities

  • Microsoft Entra ID: Your Identity Hub Free
  • Hybrid & External Identities
  • Authentication: Passwords, MFA & Passwordless
  • Password Protection & Self-Service Reset
  • Conditional Access: Smart Access Decisions
  • Entra Roles and RBAC
  • Identity Governance: Entitlements and Access Reviews
  • PIM and Identity Protection

Domain 3: Microsoft Security Solutions

  • Azure Network Defence: DDoS, Firewall & WAF
  • Azure Infrastructure Security: VNets, NSGs, Bastion & Key Vault
  • Microsoft Defender for Cloud
  • Microsoft Sentinel: SIEM Meets SOAR
  • Defender XDR: The Unified Threat Platform
  • Microsoft Defender for Office 365
  • Microsoft Defender for Endpoint
  • Defender for Cloud Apps & Defender for Identity
  • Vulnerability Management & Threat Intelligence

Domain 4: Microsoft Compliance Solutions

  • Service Trust Portal, Privacy Principles & Microsoft Priva
  • The Purview Portal & Compliance Manager
  • Data Classification & Sensitivity Labels
  • Data Loss Prevention (DLP)
  • Records Management & Retention
  • Insider Risk Management
  • eDiscovery & Audit
Domain 2: Microsoft Entra Capabilities Premium ⏱ ~10 min read

Entra Roles and RBAC

Permissions should be tied to roles, not individuals. Built-in roles, custom roles, Azure RBAC vs Entra roles, administrative units, and the principle of least privilege.

What is role-based access control (RBAC)?

☕ Simple explanation

Instead of giving each person a custom set of keys, you give them a role — and the role comes with specific keys.

Imagine a hotel. Instead of deciding which doors each individual staff member can open, you define roles: “Front Desk” can access reception and the key cabinet. “Housekeeping” can access guest rooms and the supply closet. “Manager” can access everything.

When a new housekeeper starts, you assign the “Housekeeping” role. They instantly get the right keys. When they leave, you remove the role. Done.

RBAC works the same way. You define roles with specific permissions. You assign roles to people. Permissions are never given directly to individuals.

Role-based access control (RBAC) is a permission model where access rights are assigned to roles, and roles are assigned to users. Instead of granting individual permissions to each user, administrators define roles that bundle related permissions together.

This approach simplifies permission management at scale. When an employee changes teams, you swap their role — not dozens of individual permissions. It also supports the principle of least privilege, because each role contains only the permissions needed for that function.

Microsoft Entra built-in roles

Microsoft Entra ID comes with over 80 built-in roles. Here are the ones you need to know for the exam:

RoleWhat It Can DoRisk Level
Global AdministratorFull control over the entire Entra tenant — every setting, every user, every serviceHighest — should have fewest members
User AdministratorCreate and manage users and groups, reset passwords, manage licencesMedium
Security AdministratorManage security policies, review security reports, manage Identity ProtectionHigh
Security ReaderRead-only access to security features and reportsLow
Billing AdministratorManage subscriptions and billingMedium
Helpdesk AdministratorReset passwords for non-admin users, manage service requestsLow-Medium
Exchange AdministratorManage Exchange Online settings — mailboxes, transport rules, groupsMedium
SharePoint AdministratorManage SharePoint Online sites, storage, sharing settingsMedium

Key exam concept: Global Administrator is the most powerful role. Only 2-4 people should have it. The exam frequently tests whether you know that most tasks do NOT require Global Admin — a more specific role should be used instead.

💡 Scenario: Raj cleans up admin sprawl at Lakewood

Raj runs a report and discovers 14 people have Global Administrator at Lakewood University. Some are IT staff who only manage mailboxes. Others are department heads who once needed to reset a password.

He works with management to reassign roles:

  • The Exchange team gets Exchange Administrator — they can manage mail without touching security settings
  • Helpdesk staff get Helpdesk Administrator — they can reset passwords but nothing else
  • Department heads lose all admin roles — they submit requests to the helpdesk instead

Global Admin goes from 14 members to 3: the IT Director, Raj (as backup), and a break-glass emergency account.

“Fourteen global admins is fourteen ways an attacker can own our entire tenant,” Raj tells the team.

Entra roles vs Azure RBAC roles

This distinction is critical for the exam. Microsoft has two separate role systems:

Entra roles manage identity; Azure RBAC roles manage cloud resources
FeatureMicrosoft Entra RolesAzure RBAC Roles
What they manageIdentity and access — users, groups, apps, policies in Microsoft Entra IDAzure resources — VMs, storage accounts, databases, networks in Azure subscriptions
ScopeThe Entra tenant (directory-level)Azure subscription, resource group, or individual resource
Example rolesGlobal Admin, User Admin, Security AdminOwner, Contributor, Reader, Virtual Machine Contributor
Where you assign themMicrosoft Entra admin centreAzure portal (subscription/resource level)
Use caseManaging who can sign in, reset passwords, configure MFAManaging who can create VMs, access storage, deploy apps

Key exam concept: A Global Administrator in Entra ID does NOT automatically have access to Azure resources. These are separate permission systems. However, a Global Admin can elevate themselves to Azure access if needed — but it’s a deliberate action, not automatic.

Custom roles

The built-in roles cover most scenarios, but sometimes you need a role that does not exist. Custom roles let you pick exactly which permissions to include.

FeatureDetails
What they areRoles with hand-picked permissions — you choose exactly what the role can and cannot do
Licence requirementMicrosoft Entra ID P1 or P2
When to useWhen no built-in role matches your needs (e.g., a role that can manage groups but NOT reset passwords)
How to createSelect individual permissions from a permission list, give the role a name, assign it to users
💡 Scenario: Raj creates a custom role for student assistants

Raj has student assistants who help with group management at Lakewood — adding people to class groups, removing graduates, updating group descriptions. But they should not be able to reset passwords or manage licences.

The built-in roles are either too powerful (User Administrator) or too limited (none match). So Raj creates a custom role:

  • Name: Student Group Manager
  • Permissions: Read groups, update group membership, update group properties
  • Excluded: Reset passwords, manage licences, manage users

This follows the principle of least privilege — the assistants get exactly what they need, nothing more.

Principle of least privilege

Least privilege means giving users the minimum permissions they need to do their job — and only for as long as they need them.

PrincipleWhat To DoWhat NOT To Do
Minimum permissionsGive the Helpdesk role to someone who resets passwordsGive Global Admin to everyone “just in case”
Minimum timeActivate admin access for 4 hours when neededLeave admin access permanently assigned
Minimum scopeScope a role to one department using administrative unitsGive tenant-wide access when they only manage one team

Key exam concept: The exam will present scenarios where someone is given too much access. The correct answer almost always involves assigning a more specific role with narrower permissions.

Administrative units

Administrative units let you scope role assignments to a specific part of your organisation — instead of the entire tenant.

Simple analogy: A school principal manages their own school, not every school in the district. Administrative units create these boundaries in Entra ID.

Without Administrative UnitsWith Administrative Units
A User Administrator can manage ALL 5,000 users at LakewoodA User Administrator scoped to the “Engineering Faculty” AU can only manage those 200 users
Every helpdesk staff member has tenant-wide reset abilityEach helpdesk person is scoped to their department’s AU
💡 How Raj uses administrative units

Lakewood University has four faculties: Engineering, Arts, Science, and Business. Each faculty has its own IT support person.

Raj creates four administrative units — one per faculty. He adds the relevant users to each AU. Then he assigns the Helpdesk Administrator role to each faculty’s IT person, scoped to their AU.

The result: the Engineering IT person can reset passwords for Engineering staff but cannot touch anyone in Arts, Science, or Business.

“If the Engineering IT account gets compromised,” Raj explains, “the damage is contained to one faculty — not the entire university.”

🎬 Video walkthrough

🎬 Video coming soon

Entra Roles and RBAC — SC-900 Module 6

Entra Roles and RBAC — SC-900 Module 6

~9 min

Flashcards

Question

What is role-based access control (RBAC)?

Click or press Enter to reveal answer

Answer

A permission model where access rights are assigned to roles, and roles are assigned to users. Permissions are never given directly to individuals. This simplifies management and supports least privilege.

Click to flip back

Question

What is the difference between Entra roles and Azure RBAC roles?

Click or press Enter to reveal answer

Answer

Entra roles manage identity (users, groups, apps, policies in the directory). Azure RBAC roles manage Azure resources (VMs, storage, networks in subscriptions). They are separate systems — Global Admin does not automatically have Azure resource access.

Click to flip back

Question

What are administrative units?

Click or press Enter to reveal answer

Answer

Containers that let you scope Entra role assignments to a specific part of the organisation. Instead of giving someone tenant-wide User Administrator, you scope it to an administrative unit containing only their department's users.

Click to flip back

Question

What licence is required for custom roles in Entra ID?

Click or press Enter to reveal answer

Answer

Microsoft Entra ID P1 or P2. Custom roles let you pick exactly which permissions to include when built-in roles do not match your needs.

Click to flip back

Knowledge Check

Knowledge Check

Lakewood University has 14 Global Administrators. Raj wants to follow the principle of least privilege. What should he do FIRST?

Knowledge Check

An IT administrator needs to manage Azure virtual machines but should NOT be able to manage users in Microsoft Entra ID. Which role should they be assigned?

Knowledge Check

Raj scopes the Helpdesk Administrator role to the 'Engineering Faculty' administrative unit and assigns it to Dan. What can Dan do?

← Previous

Conditional Access: Smart Access Decisions

Next →

Identity Governance: Entitlements and Access Reviews

Guided

I learn, I simplify, I share.

A Guide to Cloud YouTube Feedback

© 2026 Sutheesh. All rights reserved.

Guided is an independent study resource and is not affiliated with, endorsed by, or officially connected to Microsoft. Microsoft, Azure, and related trademarks are property of Microsoft Corporation. Always verify information against Microsoft Learn.