Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

3.3.2. Microsoft Entra Roles and RBAC

💡 First Principle: Role-based access control (RBAC) grants permissions by assigning a user to a role that already bundles a defined set of permissions — rather than assigning individual permissions one by one — which makes access both easier to grant consistently and easier to audit later, since the role itself documents what its members can do.

Microsoft Entra roles control administrative access to Entra ID itself and other Microsoft 365 services — for example, the Global Administrator or User Administrator built-in roles. This is a specific application of the least-privilege principle from Zero Trust (Phase 2.1.3): assign the narrowest built-in role that covers the job that needs doing, rather than defaulting to broad administrative access.

⚠️ Exam Trap: Microsoft Entra roles (governing Entra ID/Microsoft 365 administration) are a distinct role system from Azure RBAC (governing access to Azure resources like VMs and storage accounts) — the exam expects you to know these are two separate, parallel RBAC systems, not one.

Reflection Question: Why is assigning a narrow, purpose-built built-in role generally safer than assigning a broad administrative role "just in case" it's needed later?

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications