rspec/rules/S6385/common/description.adoc
2023-10-26 09:21:09 +02:00

9 lines
474 B
Plaintext

In Azure, the `Owner` role of a `Subscription` or a `Management group` provides
entities it is assigned to with the maximum level of privileges. The `Owner`
role allows managing all resources and assigning any role to other entities.
Because it is a powerful entitlement, it should be granted to as few users as
possible.
When a custom role has the same level of permissions as the `Owner` one, there
are greater chances that high privileges are granted to too many users.