You have an Azure subscription named Sub1 that contains a resource group named RG1.
RG1 contains a virtual network named VNet1 and a storage account named storage1. Several engineers are assigned the Owner role for Sub1.
You need to prevent updates to and deletions from VNet1. The solution must ensure that engineers can continue updating other resources in RG1.
Which lock should you apply?
Apply a Read-only lock directly to VNet1. Azure management locks operate independently of Azure RBAC and override permissions such as Owner. A ReadOnly lock prevents authorized users from both updating and deleting the locked resource, which exactly satisfies the protection requirement for VNet1. Microsoft documents that a ReadOnly lock effectively restricts authorized users to read operations for the locked resource.
The lock must be scoped specifically to VNet1, not RG1. Locks applied at a parent scope are inherited by child resources. Therefore, applying ReadOnly to RG1 would also prevent modifications to storage1 and other resources in RG1, violating the requirement that engineers must remain able to update those resources.
A Delete lock is insufficient because CanNotDelete permits users to modify a resource while preventing only deletion. The question explicitly requires preventing updates and deletions, so ReadOnly is necessary.
This aligns with the SC-500 governance objective covering enforcement of security controls for Azure resources. The current study guide places governance and security-control enforcement under Manage identity, access, and governance.
===============
Currently there are no comments in this discussion, be the first to comment!