Especially regarding the SO question, I get the feeling that author is misunderstanding something.
Where exactly are you seeing what exactly that might imply some kind of inheritance chain?
Especially regarding the SO question, I get the feeling that author is misunderstanding something.
Where exactly are you seeing what exactly that might imply some kind of inheritance chain?
You may have seen the identity's IAM page. It does not show roles assigned to the identity.
> Lower levels inherit role permissions from higher levels...When you assign a role at a parent scope, those permissions are inherited to the child scopes
https://learn.microsoft.com/en-us/azure/role-based-access-co...
so i guess this what you said is confidently wrong lmao like you couldn't even be more wrong:
> Then I'll lay it out: there is no inheritance at all. An identity does not inherit roles and it certainly does not inherit other identities.
i misspoke calling it "identity inheritance" and not "scope inheritance" tho my first comment said "role inheritance" but the fact that there is any sort of inheritance involved at all with my rbac roles is very poor design decision. and the fact that i can misunderstand this and spend hours of company time trying to understand it, and still failing....when this should be an intuitive, 101-level thing for cloud design. but nah i gotta spend time going through like ten different docs piecing together knowledge and pentest my own work and also argue with some guy on the internet who called himself adept at azure and doesn't know this either (which further proves my point!)
What I wrote is, in fact, accurate. An identity cannot inherit a role. It is simply impossible. What would it inherit from? The identity does not actually exist where it appears in the control plane (ie. in a resource group). It exists in Entra ID (formerly Azure AD).
There is but one possibility for a newly created identity to actually have roles assignments: Automation via policy. Now that I think about it, there might be another: assigning roles to special groups like "Authenticated users".
yes, exactly!