gpt4 book ai didi

azure - 所有者可以删除 Azure 中的只读或不可删除锁定吗?

转载 作者:行者123 更新时间:2023-12-03 07:02:21 24 4
gpt4 key购买 nike

我对 Azure 资源 block 有疑问。通过向资源添加只读或不可删除锁,当您点击删除时,该资源将无法被删除。所以我的问题是,该锁可以由所有者移除吗?有没有可能让锁的主人也无法解锁?

最佳答案

Who can create or delete locks

To create or delete management locks, you must have access to Microsoft.Authorization/* or Microsoft.Authorization/locks/* actions. Of the built-in roles, only Owner and User Access Administrator are granted those actions.

来源:Lock resources to prevent unexpected changes - Who can create or delete locks .

简而言之:答案是否定的。
此外,owner 是 Azure 中权限最高的角色,因为它

Grants full access to manage all resources, including the ability to assign roles in Azure RBAC.

来源:Azure built-in roles - All .

如果您按照 Principal of Least Privilege 工作,您应该限制 Azure 订阅的所有者数量。

The Owner role grant full access to manage all resources, including the ability to assign roles in Azure RBAC. You should have a maximum of 3 subscription owners to reduce the potential for breach by a compromised owner.

关于azure - 所有者可以删除 Azure 中的只读或不可删除锁定吗?,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/72125138/

24 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com