4 ms·
What inheritance chain? I'd say I'm quite proficient with Azure RBAC and I cannot understand what you're describing.
by fuzzy2 1y ago
What inheritance chain? I'd say I'm quite proficient with Azure RBAC and I cannot understand what you're describing.
- greenie_beans 1y agohttps://learn.microsoft.com/en-us/answers/questions/969822/how-to-disable-rbac-inheritance-over-resources-on https://learn.microsoft.com/en-us/answers/questions/969822/h... and https://stackoverflow.com/questions/76618129/prevent-roles-from-being-inherited-by-a-managed-identity https://stackoverflow.com/questions/76618129/prevent-roles-f...
- fuzzy2 1y agoThese don't clarify your situation, sorry. They're also referring to two distinct scenarios. Especially regarding the SO question, I get the feeling that author is misunderstanding something. Where exactly are you seeing what exactly that might imply some kind of inheritance chain?
- greenie_beans 1y agoi get the sense that you're not trying to help but instead argue about it. i already described as much as i want to detail: https://news.ycombinator.com/item?id=44445382 https://news.ycombinator.com/item?id=44445382
- fuzzy2 1y agoOkay. Then I'll lay it out: there is no inheritance at all. An identity does not inherit roles and it certainly does not inherit other identities. You are misinterpreting something you saw. However, without further details, a more targeted answer is not possible. I did not want to write a blanket statement like that because it is very condescending and hostile. Sorry about that. You may have seen the identity's IAM page. It does not show roles assigned to the identity.
- greenie_beans 1y agofrom the docs: > Lower levels inherit role permissions from higher levels...When you assign a role at a parent scope, those permissions are inherited to the child scopes https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-steps#step-3-identify-the-needed-scope https://learn.microsoft.com/en-us/azure/role-based-access-co... so i guess this what you said is confidently wrong lmao like you couldn't even be more wrong: > Then I'll lay it out: there is no inheritance at all. An identity does not inherit roles and it certainly does not inherit other identities. i misspoke calling it "identity inheritance" and not "scope inheritance" tho my first comment said "role inheritance" but the fact that there is any sort of inheritance involved at all with my rbac roles is very poor design decision. and the fact that i can misunderstand this and spend hours of company time trying to understand it, and still failing....when this should be an intuitive, 101-level thing for cloud design. but nah i gotta spend time going through like ten different docs piecing together knowledge and pentest my own work and also argue with some guy on the internet who called himself adept at azure and doesn't know this either (which further proves my point!)
- fuzzy2 1y agoThe so-called "lower levels" inherit role permissions (or role assignments, if you will), which is something else entirely. Furthermore I'd say this is both expected and necessary to effectively administer permissions in organizations. Assigning permissions (via roles or otherwise) on every single object is not feasible. Inheritance is required. It works similarly to NTFS ACLs. What I wrote is, in fact, accurate. An identity cannot inherit a role. It is simply impossible. What would it inherit from? The identity does not actually exist where it appears in the control plane (ie. in a resource group). It exists in Entra ID (formerly Azure AD). There is but one possibility for a newly created identity to actually have roles assignments: Automation via policy. Now that I think about it, there might be another: assigning roles to special groups like "Authenticated users".
- greenie_beans 1y agook so now it's a semantic debate. love that... i hope this knowledge that i shared is useful to you in the future, so you can avoid dumb ass RBAC inheritance footguns