Skip to content

002. Restricting Role Assignments to Dedicated az_accounts

Date: 03-13-2025

State: Proposed/Accepted/Deprecated/Superseded

Status: Accepted

Context

Enterprise security and governance policies mandate that privileged operations and elevated permissions must be associated only with dedicated Azure AD user accounts (commonly referred to as az_accounts). These accounts are created and managed under the organization's secure identity lifecycle processes. Using az_accounts avoids confusion caused by personal accounts or service principals, ensures clearer auditing and traceability, and reduces the risk of unauthorized privilege escalation.

Additionally, limiting role assignments to az_accounts aligns with strict compliance requirements that stipulate controlled identity governance, whereby each account's validity and ownership can be tracked and regularly reviewed. This approach makes it easier to revoke or update permissions if a user leaves or changes roles.

Decision

We have agreed to only allow az_accounts to receive RBAC role assignments for privileged actions in Azure. This means:

  1. No external/personal accounts: Non-corporate or personal Microsoft accounts must not be granted RBAC roles.
  2. No nested group approaches that include other identity types: We avoid chaining groups with external members into our subscription RBAC, thereby ensuring only approved az_accounts can activate privileges.

Consequences

  • Enhanced Security & Compliance: All privileged access is tied to properly managed accounts, satisfying governance and audit requirements.
  • Clearer Audit Trails: Audit logs show exactly which user (via their az_account) performed an elevated action, simplifying investigations.
  • Operational Adjustments: Users accustomed to personal or default accounts must switch to az_accounts, which may require new onboarding.

Last update: 2026-09-14