title | description | services | documentationCenter | author | manager | editor | ms.service | ms.devlang | ms.topic | ms.tgt_pltfrm | ms.workload | ms.date | ms.author | ms.custom |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Tutorial: Grant a user access to Azure resources using the Azure portal - Azure RBAC |
In this tutorial, learn how to grant a user access to Azure resources using the Azure portal and Azure role-based access control (Azure RBAC). |
role-based-access-control |
rolyon |
karenhoran |
role-based-access-control |
tutorial |
identity |
10/15/2021 |
rolyon |
subject-rbac-steps |
Azure role-based access control (Azure RBAC) is the way that you manage access to Azure resources. In this tutorial, you grant a user access to create and manage virtual machines in a resource group.
In this tutorial, you learn how to:
[!div class="checklist"]
- Grant access for a user at a resource group scope
- Remove access
If you don't have an Azure subscription, create a free account before you begin.
Sign in to the Azure portal at https://portal.azure.com.
-
In the navigation list, click Resource groups.
-
Click New to open the Create a resource group page.
-
Select a subscription.
-
For Resource group name, enter example-group or another name.
-
Click Review + create and then click Create to create the resource group.
-
Click Refresh to refresh the list of resource groups.
The new resource group appears in your resource groups list.
In Azure RBAC, to grant access, you assign an Azure role.
-
In the list of Resource groups, open the new example-group resource group.
-
In the navigation menu, click Access control (IAM).
-
Click the Role assignments tab to see the current list of role assignments.
-
Click Add > Add role assignment.
If you don't have permissions to assign roles, the Add role assignment option will be disabled.
-
On the Role tab, select the Virtual Machine Contributor role.
-
On the Members tab, select yourself or another user.
-
On the Review + assign tab, review the role assignment settings.
-
Click Review + assign to assign the role.
After a few moments, the user is assigned the Virtual Machine Contributor role at the example-group resource group scope.
In Azure RBAC, to remove access, you remove a role assignment.
-
In the list of role assignments, add a checkmark next to the user with the Virtual Machine Contributor role.
-
Click Remove.
-
In the remove role assignment message that appears, click Yes.
-
In the navigation list, click Resource groups.
-
Click example-group to open the resource group.
-
Click Delete resource group to delete the resource group.
-
On the Are you sure you want to delete pane, type the resource group name and then click Delete.
[!div class="nextstepaction"] Tutorial: Grant a user access to Azure resources using Azure PowerShell