ABAC Support for Azure Built-in Roles
You have an Azure subscription that contains a resource group named RG1 and four users named User1, User2, User3, and User4. You plan to assign the users the following roles for RG1: • User1: Reader • User2: Contributor • User3: Storage Blob Data Reader • User4: Virtual Machine Contributor You are evaluating the use of attribute-based access control (ABAC). Which user's role will support the use of ABAC?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests knowledge of ABAC scope limitations; the common trap is assuming all RBAC roles support fine-grained conditionals like Contributor or Virtual Machine Contributor.
This question evaluates which Azure built-in role supports Attribute-Based Access Control (ABAC) conditions. The correct answer is Storage Blob Data Reader, as ABAC is currently limited to specific data plane roles.
Many candidates choose User2 (Contributor) because it is a broad management role, but ABAC conditions are not available for general management roles, only for specific data actions like blob storage.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Attribute-Based Access Control (ABAC) in Azure allows you to define conditions on role assignments based on tags, resource types, and other attributes. However, this feature is currently supported only for specific built-in roles that involve data plane actions, particularly for Azure Blob Storage and Azure Queue Storage. The 'Storage Blob Data Reader' role is explicitly listed in Microsoft documentation as supporting these conditions.Why the Other Options Are Wrong
User1 (Reader) and User2 (Contributor) are management-level roles that do not support ABAC conditions at this time. Similarly, User4 (Virtual Machine Contributor) is a compute management role and lacks the necessary data action permissions required for ABAC implementation. Only roles with specific data plane permissions (like blob read/write) enable the 'Conditions' tab in the Azure portal.Community Comment Notes
Community consensus strongly favors Option C. As noted by user penatuna, testing in the Azure portal confirms that the Conditions tab is greyed out for Reader, Contributor, and VM Contributor, but active for Storage Blob Data Reader. Official Microsoft documentation also lists 'Storage Blob Data Reader' among the roles supporting ABAC conditions.Official Reference
Exam Strategy
When studying for SC-300, memorize the specific built-in roles that support ABAC conditions. Focus on data plane roles related to Blob Storage, Data Lake Gen2, and Key Vault, as these are the primary candidates for ABAC questions.
Frequently Asked Questions
Does Contributor role support ABAC?
No, the Contributor role is a management role and does not support ABAC conditions. ABAC is currently limited to specific data plane roles.
Why is Virtual Machine Contributor wrong for ABAC?
Virtual Machine Contributor manages compute resources but lacks the specific data actions (like blob storage) required to enable ABAC conditions.
Related Analysis
Practice All SC-300 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-300 Practice Test →