Last updated: April 29, 2026
Module 9 (Cloud track) covered privesc paths. This module is the operational guide.
Scope hierarchy
Management Group → Subscription → Resource Group → Resource. Inheritance flows down. Least-privilege principle: assign at the lowest scope possible.
Built-in roles to know
- Owner — full control + can manage access
- Contributor — full control without manage-access
- Reader — read-only
- User Access Administrator — can manage access (but not resources)
- Service-specific: Storage Blob Data Contributor, Network Contributor, etc.
Custom roles
For least-privilege: define your own. Limit to specific actions/dataActions/notActions.
PIM (Privileged Identity Management)
Eligible vs Active assignments. User can activate role for limited time with MFA + justification. Audit trail. Standard for any privileged role in 2026.
Module Quiz · 6 questions
Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.