Secure New Employee Access in Azure
Grant, audit, and revoke scoped Azure access for a new support analyst.
Introduction
30 Second Summary
New employees need enough access to do their jobs from day one. Broad permissions can expose systems they never need to touch.
In this project, you will build a browser-only access lab in the Microsoft Azure portal for onboarding a support analyst with least privilege.
What You'll Build
You will show someone the portal proving that Support Analyst has Reader access only to nw-access-lab-rg.
By the end of this project, you'll have:
- A protected resource boundary named nw-access-lab-rg that you can open in the portal.
- A group-managed employee identity you can show in Microsoft Entra ID. The support-analyst user belongs to gp-rg-readers.
- A permission trail that connects the Reader assignment in Check access to its record in Azure Monitor Activity Log.
- Secret Mission: Revoke the Reader assignment. Prove the user lost access in Check access. Find the removal event in Activity log.
Are there any prerequisites?
The lab runs in a modern browser on Windows with an active Azure subscription. A new Azure free account requires a phone number plus a non-prepaid credit or debit card.
It also requires a Microsoft or GitHub account.
Before We Start
Safe onboarding begins with a clear limit on what a new employee can access. This project gives a support analyst read-only access to one resource group without subscription-wide permissions or resource modification rights.
Set Up and Verify Azure Access
The access lab can only create a protected boundary when the signed-in account can reach an active Azure subscription. It also needs administrative permission for the role assignment you will add later.
This step stays entirely in your browser. You do not need a code editor or command-line tool.
You will confirm the active subscription in the Microsoft Azure portal. You will also confirm that Microsoft Entra ID opens in the selected directory.
In this step, get ready to:
- Prepare an Azure account with an active subscription.
- Verify the active subscription in the Microsoft Azure portal.
- Confirm Microsoft Entra ID opens in the selected directory.
Choose your Azure account path
An Azure account gives you access to the subscription that holds the lab. You can use an existing active subscription or create an Azure free account.
Before Card Verification
Card verification can feel like a purchase. The Azure free account is not charged unless you decide to move to pay-as-you-go pricing.
Microsoft may place a temporary one-dollar or equivalent authorization hold on your card. The hold is removed after verification.
- Use your existing Azure account if it already has an active subscription.
- Prepare a phone number, a non-prepaid credit or debit card, and a Microsoft or GitHub account if you need to create an account.
- Open the official Azure account page.
- Choose the Azure free account if you are eligible.
- Complete the About you section.
- Complete the Identity verification by phone section.
- Complete the Identity verification by card section.
- Complete the Agreement section.
Good progress. Your Azure account is ready for the browser checks that prove the lab can continue.
Signup Not Completing?
- Check that the card you entered is not prepaid.
- Follow the official Azure signup troubleshooting guide for help with the verification sections.
- Help me troubleshoot an Azure account signup problem.
Verify your active subscription
The Subscriptions page shows which Azure subscription the current account can use. An active listing confirms that the lab has a place to create its protected boundary.
The first portal sign-in can ask you to register for multifactor authentication. This protects administrative access to your Azure resources.
- Go to the Microsoft Azure portal.
- Sign in with the same account you prepared in the previous substep.
- Complete any multifactor authentication registration shown during sign-in.
- Select the portal search bar at the top of the page.
- Enter Subscriptions.
- Select Subscriptions from the search results.
- Confirm that your subscription is listed as active.
- Ask the subscription administrator to confirm that your account can create resource groups and manage role assignments if the subscription belongs to an organisation.
You should see at least one active subscription associated with the signed-in account.
Seeing No Subscriptions Found?
The directory selector can be easy to miss because it sits inside the account menu. The selected directory determines which subscriptions the portal displays.
- Select your account menu in the portal header.
- Check which Azure directory is currently selected.
- Switch to the directory that contains your subscription.
- Confirm that your account has Owner access if No subscriptions found remains visible.
- Help me find my Azure subscription in the correct directory.
Confirm Microsoft Entra ID access
Microsoft Entra ID is the directory that manages the employee identity and security group used later in the lab. Its Overview page confirms that the signed-in administrator can reach the selected directory.
- Select the portal search bar at the top of the page.
- Enter Microsoft Entra ID.
- Select Microsoft Entra ID from the search results.
- Select Overview from the left menu if another page opens first.
- Confirm that the Overview page loads for the selected directory.
Microsoft Entra ID Not Loading?
- Check the selected directory from your account menu.
- Return to the directory that contains your active subscription.
- Ask your Azure administrator to confirm that your account can access the Microsoft Entra tenant.
- Help me troubleshoot access to Microsoft Entra ID.
Before the final check, decide whether you expect both portal pages to load for the signed-in administrator.
- Return to Subscriptions using the portal search bar.
- Confirm that the active subscription remains visible.
- Return to Microsoft Entra ID using the portal search bar.
- Confirm that its Overview page loads in the selected directory.
Your Access Checkpoint
An active Azure subscription is available to the signed-in administrator in the Azure portal.
The selected Microsoft Entra ID directory is accessible. Its Overview page loads for the signed-in administrator.
The signed-in administrator can create resource groups and manage role assignments.
That is the account groundwork complete. Your browser session can now reach the Azure subscription and its identity directory.
Your Azure access is ready. Next, you will create the narrow resource boundary that keeps the analyst's future permissions away from the rest of the subscription.
Create the Protected Resource Boundary
Your active subscription is ready in the Microsoft Azure portal. The next job is to prepare a safe boundary for the support analyst.
Least privilege works best when permissions have a narrow scope. An empty resource group called nw-access-lab-rg keeps later access away from the whole subscription.
In this step, get ready to:
- Open the resource group creation form.
- Configure nw-access-lab-rg in your active subscription.
- Confirm the empty resource group opens as your protected boundary.
Open the resource group form
The Resource groups page lists every resource group in the selected subscription. Its creation form captures the details for a new one.
- In the Azure portal tab from earlier, select the search bar at the top of the page.
- Enter Resource groups.
- Select Resource groups from the search results.
- Select Create in the toolbar.
You'll see the resource group creation page with fields for the subscription, group name, and region.
Why use a resource group?
Azure can apply permissions at several scopes. A resource group gives this lab one narrow target.
The group can stay empty while you test access control. No workload resources are needed.
Configure the narrow boundary
The active subscription owns the new boundary. The fixed values make the boundary easy to recognize.
- In Subscription, select the active subscription you verified earlier.
- In Resource group, enter nw-access-lab-rg.
You can now see the existing subscription above the new nw-access-lab-rg boundary.
- In Region, select Central US.
- Select Review + Create.
You should see nw-access-lab-rg, Central US, and your active subscription on the review page.
- Select Create to create the resource group.
You've got the boundary in place. nw-access-lab-rg now exists without any deployed resources.
Can't create the resource group?
- Check that Subscription shows the active subscription from earlier.
- Check that Resource group contains nw-access-lab-rg exactly.
- Select Central US again if Region is blank.
- Help me troubleshoot creating nw-access-lab-rg in the Azure portal.
Verify the protected boundary
The creation confirmation proves Azure accepted the request. The final check proves the group is available as the scope you will use later.
- Predict whether nw-access-lab-rg now appears in the active subscription's resource group list.
- Return to Resource groups in the Azure portal.
- Reload the browser page if nw-access-lab-rg is not listed yet.
- Select nw-access-lab-rg from the list.
You'll see nw-access-lab-rg open under your active subscription with Central US in its details. The resource list is empty.
Can't find the resource group?
- Confirm you are still in the directory that showed your active subscription earlier.
- Reload the Resource groups page after a short wait.
- Help me find nw-access-lab-rg in my Azure subscription.
Your narrow resource boundary is ready. Next up, you'll create the support identity with no resource access.
Create the Support Analyst Identity
Your empty resource group now gives this lab a narrow boundary in the Microsoft Azure portal.
A cloud identity should begin with no resource permissions. This creates a clean access baseline for a new employee.
You will create Support Analyst in Microsoft Entra ID. A security group will hold the employee while Check access tests the current permissions.
In this step, get ready to:
- Create the gp-rg-readers security group.
- Create Support Analyst as a member of gp-rg-readers.
- Check the employee's current access at nw-access-lab-rg.
Create the security group
Groups give administrators one place to manage people who need the same permissions. Assigned membership gives you direct control over who belongs to this group.
- Return to the Microsoft Azure portal tab from earlier.
- Type Microsoft Entra ID into the search bar.
- Select Microsoft Entra ID from the search results.
- Select Groups from the left menu.
- Select All groups.
- Select New group.
- Choose Security for Group type.
- Enter gp-rg-readers in Group name.
- Choose Assigned for Membership type.
- Select Create.
- Confirm that gp-rg-readers appears in the group list.
The management layer is now in place. Future access assignments can target this group instead of each employee separately.
Why use a group?
Group-based access keeps permission management consistent as employees join or leave a team. The role can remain attached to the group while its membership changes.
Unable to create the group?
- Confirm that Security is selected for Group type.
- Check whether your administrator account has the User Administrator or Groups Administrator role.
- Use the exact group name gp-rg-readers.
- Help me troubleshoot Microsoft Entra group creation.
Create Support Analyst as a group member
The employee needs a separate user object before the group can manage their access. The user principal name gives that identity a tenant-specific sign-in name.
- Select Users from the Microsoft Entra ID menu.
- Select New user.
- Select Create new user.
- Enter support-analyst in User principal name.
- Enter Support Analyst in Display name.
- Leave the generated value in Password in place.
The generated initial password is a live credential. Careful handling here keeps the test identity secure.
- Store the generated initial password in a private credential manager.
- Record the full value shown in User principal name here: your tenant-specific user principal name.
- Select Review + create.
- Select Create.
Support Analyst now appears in the user list with the tenant-specific user principal name you recorded.
- Select Groups from the Microsoft Entra ID menu.
- Select All groups.
- Select gp-rg-readers from the group list.
- Select Members.
- Select + Add members.
- Search for Support Analyst.
- Choose Support Analyst from the results.
- Select Select.
The Members page now lists Support Analyst. Your employee identity is managed through gp-rg-readers.
Support Analyst missing from the group?
- Refresh the group page if Support Analyst is missing from the member picker.
- Confirm that the user list contains the display name Support Analyst.
- Check that you opened gp-rg-readers before selecting + Add members.
- Help me add Support Analyst to the security group.
Check the employee's current access
Check access calculates effective permissions from Azure role-based access control assignments at the selected scope. Testing now gives you a baseline before any resource role is assigned.
- Type nw-access-lab-rg into the portal search bar.
- Select nw-access-lab-rg from the search results.
- Select Access control (IAM) from the resource group menu.
Before you check, do you expect Support Analyst to have an effective role at this resource group?
- Select Check access.
- Select Check access in the pane.
- Choose User, group, or service principal.
- Search for Support Analyst.
- Select Support Analyst.
The assignments pane does not list Reader. This visible access gap is the intended result.
What have you proved?
- The gp-rg-readers security group uses Assigned membership.
- Support Analyst is a member of gp-rg-readers.
- The generated initial password remains private.
- Support Analyst has no Reader assignment at nw-access-lab-rg.
Reader appears unexpectedly?
- Confirm that the assignments pane is showing Support Analyst.
- Confirm that the current resource group is nw-access-lab-rg.
- Inspect the listed assignment's scope before changing any existing access.
- Help me investigate an unexpected Reader assignment.
Your employee identity now has a group-managed home plus a proven no-access baseline. Next, you will grant read-only access at the resource group scope.
Grant Scoped Reader Access
Your earlier access check in the Microsoft Azure portal proved that Support Analyst has no Reader access to nw-access-lab-rg. That clean starting point makes the permission change measurable.
You will use Azure role-based access control (Azure RBAC) to assign Reader to gp-rg-readers at the resource group scope. The role allows viewing without changes.
Keeping the assignment on nw-access-lab-rg applies least privilege to the employee's access. The active subscription remains outside this lab's assignment.
In this step, get ready to:
- Choose the Reader role at the resource group scope.
- Assign the security group as the role member.
- Confirm Support Analyst receives Reader access through the group.
Choose Reader at the resource group scope
An Azure RBAC role assignment connects one role to one principal within one scope. Starting from nw-access-lab-rg fixes that scope to the resource group.
- Return to nw-access-lab-rg in the Azure portal from earlier.
- Select Access control (IAM) from the left menu.
- Select Role assignments.
- Select Add.
- Select Add role assignment.
- On the Role tab, select Job function roles.
- Select Reader.
- Select Next.
You should now see the Members step. The selected role should show Reader.
Assign the security group
Assigning the role to the security group in Microsoft Entra ID makes group membership the control point. Support Analyst receives the permission through existing membership in gp-rg-readers.
- On the Members tab, choose User, group, or service principal.
- Select Select members.
- Enter gp-rg-readers in the search box.
- Select gp-rg-readers from the search results.
- Select Select.
- Select Review + assign.
The review page should show Reader for gp-rg-readers. The scope should be nw-access-lab-rg.
- Select Review + assign again.
You have closed the access gap with one group-based assignment. The Role assignments list should show Reader for gp-rg-readers at nw-access-lab-rg.
Can't Assign the Group?
- Wait a few minutes if gp-rg-readers does not appear in the member picker.
- Confirm that your signed-in administrator can assign Azure roles if Add role assignment is unavailable.
- Help me troubleshoot this Azure role assignment.
Verify effective access for Support Analyst
Effective access includes permissions inherited through group membership. Check access resolves the group assignment into the permission that Support Analyst receives.
Before you check again, predict whether the employee's assignments pane reflects the group role.
- In Access control (IAM) for nw-access-lab-rg, select Check access.
- Select Check access in the pane.
- Choose User, group, or service principal.
- Search for Support Analyst.
- Select Support Analyst.
You should see Reader in the assignments pane for Support Analyst. The assignment scope should be nw-access-lab-rg.
This lab has created no Reader assignment at the active subscription scope. The employee receives read-only access through membership in gp-rg-readers.
Reader Not Showing Yet?
Role assignment changes can take up to 10 minutes to take effect. A short delay here is normal.
- Wait up to 10 minutes.
- Refresh Check access.
- Select Support Analyst again.
- Help me find the missing Reader assignment.
That is least privilege in action. Support Analyst now has read-only access to this one resource group through group membership.
The scoped permission is working. Next, you will trace this access change through Azure's audit record.
Audit the Role Assignment
The Azure RBAC Reader assignment now gives Support Analyst effective read-only access through gp-rg-readers. Its scope stays limited to nw-access-lab-rg.
Access that cannot be traced is difficult to investigate. In this step, you will use Azure Monitor Activity Log to connect the permission change to the administrator who made it.
In this step, get ready to:
- Open the Activity log for nw-access-lab-rg.
- Filter the current session to isolate the role-assignment creation.
- Inspect the successful event to verify its audit details.
Open the resource group's Activity log
Azure Monitor records management operations for Azure resources in the Activity log. Opening the log from the resource group keeps the evidence focused on the boundary where you granted access.
- Switch back to the nw-access-lab-rg resource group from earlier.
- Select Activity log from the resource group menu.
- Set the time range to cover your current portal session.
You should see management events associated with nw-access-lab-rg. The filters above the event list help you isolate the access change.
Why start from the resource group?
The resource group's Activity log focuses the audit trail on operations that affected nw-access-lab-rg.
This view makes the resource group boundary visible in the evidence you inspect.
Filter the current session
Activity log entries are typically available within 3 to 20 minutes. A short wait is expected if the assignment was created recently.
- Open the Operation filter.
- Select Create role assignment.
The list should now focus on role-assignment creation events within the selected time range.
- Open the Event initiated by filter.
- Select your signed-in administrator identity.
You should now see the role-assignment creation event from the current session.
Can't find the event?
- Broaden the time range to include the moment when you assigned the Reader role.
- Clear the Event initiated by filter if your account uses a different display name.
- Refresh the Activity log after 20 minutes have passed.
Help me locate the missing role-assignment event.
Inspect the assignment event
The event details connect the permission change to its initiating account. They also show when the operation occurred within the resource group boundary.
Before you open the event, which account do you expect to see as the initiator?
- Select the successful Create role assignment event.
- Confirm that the Status field shows a successful operation.
- Confirm that the Event initiated by field matches your signed-in administrator identity.
- Confirm that the timestamp falls within your current session.
- Confirm that the scope identifies nw-access-lab-rg.
The Status field should show that the operation succeeded. The Event initiated by field should match your signed-in administrator account.
The timestamp should match when you granted access. The scope should identify nw-access-lab-rg as the affected resource group.
Well done. Your scoped Reader assignment now has an audit record that shows who created it.
Secret mission
Revoke Access and Prove It Is Gone
Remove the group's Reader assignment. Prove Support Analyst lost effective access. Trace the revocation in the audit record.
Clean Up Your Resources
Clean Up Your Resources
Your empty resource group and test identities create no ongoing workload costs in Microsoft Azure. Choose whether to keep the lab for later, pause your session, or delete its resources entirely.
Resources you used:
- An empty Azure resource group named nw-access-lab-rg.
- A Microsoft Entra ID security group named gp-rg-readers.
- A Microsoft Entra ID user with the username support-analyst.
Keep everything running
No action is needed. Choose this option if you want to reuse the identity lab for another access exercise.
- Leave nw-access-lab-rg available as an empty permission boundary.
- Keep gp-rg-readers for another group-based access exercise.
- Keep support-analyst as a test identity.
The Reader assignment stays removed. Support Analyst remains without access to nw-access-lab-rg.
Pause - I'll come back to this later
Signing out pauses your work because no workload is running. The resource group and test identities stay in your tenant for later.
- Select your account icon in the top-right corner of the Microsoft Azure portal.
- Select Sign out.
- Sign in with the same administrator account when you are ready to resume.
Delete - I don't want to use this again
Deleting the lab is permanent, but it only removes the empty boundary and test identities you created. Your active Azure subscription stays available.
The Reader assignment from the Secret Mission is already removed. Cleanup starts with the test user.
Delete the test user:
- Use the portal search bar to search for Microsoft Entra ID.
- Select Microsoft Entra ID from the search results.
- Select Users in the left menu.
- Select the user with the display name Support Analyst.
- Select Delete user.
- Complete the confirmation shown by the portal.
- Return to the Users list.
- Confirm that Support Analyst no longer appears.
Delete the security group:
- Select Groups in the Microsoft Entra ID left menu.
- Select All groups.
- Select gp-rg-readers.
- Select Delete.
- Complete the confirmation shown by the portal.
- Return to the All groups list.
- Refresh the group list.
- Confirm that gp-rg-readers no longer appears.
Delete the empty resource group:
- Return to the Azure portal search bar.
- Search for Resource groups.
- Select Resource groups from the search results.
- Select nw-access-lab-rg.
- Select Delete resource group.
- Follow the portal confirmation prompt to finish deleting the resource group.
- Refresh the Resource groups list.
- Confirm that nw-access-lab-rg no longer appears.
Nice Work!
Nice Work!
You did it. You completed a least-privilege employee access lifecycle in Microsoft Azure.
You've learned how to:
- Create a narrow resource group boundary named nw-access-lab-rg for permissions at a limited scope.
- Model an employee identity in Microsoft Entra ID through the support-analyst user and gp-rg-readers security group. Grant the Reader role through Azure RBAC at resource group scope.
- Verify effective access through Access control (IAM) and Check access. Trace the successful Create role assignment event through Azure Monitor Activity Log.
- Complete the optional Secret Mission by revoking the Reader assignment from gp-rg-readers. Confirm its disappearance in Check access. Locate the removal event in the Activity log.
Ready to quiz yourself?