Management & GovernanceQuestion 84 of 100
Which built-in RBAC role lets a user manage resources but NOT grant access to other users?
a.Owner
b.Reader
c.Guest
d.Contributor
Explanation
The Contributor role allows creating and managing all types of resources but does not permit assigning roles to others. That role-assignment capability is reserved for Owner and User Access Administrator. This separation supports controlled delegation.
Practice all 100 questions free — no signup required.
Related questions on this topic
- Which Azure governance tool would you use to package policies, role assignments, and resource templates as a repeatable, enforceable set?
- What does the principle of 'least privilege' mean when assigning RBAC roles?
- Which built-in RBAC role grants full access to manage all resources, including assigning roles to others?
- Which built-in RBAC role provides view-only access with no ability to make changes?
- What is the main benefit of applying consistent tagging across your Azure resources?
- Which service helps you improve your organization's security posture by providing a security score and recommendations?
Last reviewed: · editorial process
PrepPass Editorial Team · Verified against Microsoft Azure Fundamentals (AZ-900) · How we review