002. Restricting Role Assignments to Dedicated az_accounts
Date: 03-13-2025
State: Proposed/Accepted/Deprecated/Superseded
Status: Accepted
Context
Enterprise security and governance policies mandate that privileged operations and elevated permissions must be associated only with dedicated Azure AD user accounts (commonly referred to as az_accounts). These accounts are created and managed under the organization's secure identity lifecycle processes. Using az_accounts avoids confusion caused by personal accounts or service principals, ensures clearer auditing and traceability, and reduces the risk of unauthorized privilege escalation.
Additionally, limiting role assignments to az_accounts aligns with strict compliance requirements that stipulate controlled identity governance, whereby each account's validity and ownership can be tracked and regularly reviewed. This approach makes it easier to revoke or update permissions if a user leaves or changes roles.
Decision
We have agreed to only allow az_accounts to receive RBAC role assignments for privileged actions in Azure. This means:
- No external/personal accounts: Non-corporate or personal Microsoft accounts must not be granted RBAC roles.
- No nested group approaches that include other identity types: We avoid chaining groups with external members into our subscription RBAC, thereby ensuring only approved
az_accountscan activate privileges.
Consequences
- Enhanced Security & Compliance: All privileged access is tied to properly managed accounts, satisfying governance and audit requirements.
- Clearer Audit Trails: Audit logs show exactly which user (via their
az_account) performed an elevated action, simplifying investigations. - Operational Adjustments: Users accustomed to personal or default accounts must switch to
az_accounts, which may require new onboarding.