ABAC Support for Azure Built-in Roles

Plan, implement, and manage access reviews in Microsoft Entra
Answer Correct answer: C — Storage Blob Data Reader supports ABAC because it is one of the few built-in roles with data plane actions that allow conditional access.

You have an Azure subscription that contains a resource group named RG1 and four users named User1, User2, User3, and User4. You plan to assign the users the following roles for RG1: • User1: Reader • User2: Contributor • User3: Storage Blob Data Reader • User4: Virtual Machine Contributor You are evaluating the use of attribute-based access control (ABAC). Which user's role will support the use of ABAC?

  1. User1
  2. User2
  3. User3 Correct Answer
  4. User4

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests knowledge of ABAC scope limitations; the common trap is assuming all RBAC roles support fine-grained conditionals like Contributor or Virtual Machine Contributor.

This question evaluates which Azure built-in role supports Attribute-Based Access Control (ABAC) conditions. The correct answer is Storage Blob Data Reader, as ABAC is currently limited to specific data plane roles.

Many candidates choose User2 (Contributor) because it is a broad management role, but ABAC conditions are not available for general management roles, only for specific data actions like blob storage.

Community Discussion (7 comments)

YesPlease 👍 1 Selected: C
Answer C) User3 (Storage Blob Data Reader) supports ABAC Currently, conditions can be added to built-in or custom role assignments that have blob storage or queue storage data actions. These include the following built-in roles: Storage Blob Data Contributor Storage Blob Data Owner Storage Blob Data Reader Storage Queue Data Contributor Storage Queue Data Message Processor Storage Queue Data Message Sender Storage Queue Data Reader https://learn.microsoft.com/en-us/azure/role-based-access-control/conditions-format#actions
Labelfree 👍 1 Selected: C
C - Only User3: Storage Blob Data Reader supports ABAC.
penatuna 👍 3 Selected: C
Within the roles in the question, only User3: Storage Blob Data Reader supports the use of ABAC. You can test this yourself by adding role assignment in Azure. The Conditions tab is greyed out with all the other roles in the question. If you choose Storage Blob Data Reader, you can fill out the conditions.
RemmyT 👍 2
User3 : Storage Blob Data Reader Example Azure role assignment conditions for Blob Storage Azure attribute-based access control (Azure ABAC) is generally available (GA) for controlling access to Azure Blob Storage, Azure Data Lake Storage Gen2, and Azure Queues using request, resource, environment, and principal attributes in both the standard and premium storage account performance tiers. https://learn.microsoft.com/en-us/azure/storage/blobs/storage-auth-abac-examples?tabs=portal-visual-editor
klayytech 👍 4 Selected: C
Attribute-based access control (ABAC) grants access based on attributes of users, resources, and the environment. - User roles (User1, User2, User3, User4) are a simpler form of access control. Out of the options, only Storage Blob Data Reader and Virtual Machine Contributor roles are specific to resource types (Storage Blob and Virtual Machine). These roles suggest ABAC might be used for finer-grained control. So, the answer is either C or D. While both Storage Blob Data Reader and Virtual Machine Contributor roles might be used with ABAC, it's more likely for data access. Therefore, the most likely user to benefit from ABAC is User3: Storage Blob Data Reader. So the answer is: C. User3
RASUK 👍 2
C https://learn.microsoft.com/en-us/azure/role-based-access-control/conditions-overview
spatrick 👍 1
Currently, conditions can be added to built-in or custom role assignments that have blob storage or queue storage data actions. Conditions are added at the same scope as the role assignment. Just like role assignments, you must have Microsoft.Authorization/roleAssignments/write permissions to add a condition.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Attribute-Based Access Control (ABAC) in Azure allows you to define conditions on role assignments based on tags, resource types, and other attributes. However, this feature is currently supported only for specific built-in roles that involve data plane actions, particularly for Azure Blob Storage and Azure Queue Storage. The 'Storage Blob Data Reader' role is explicitly listed in Microsoft documentation as supporting these conditions.

Why the Other Options Are Wrong

User1 (Reader) and User2 (Contributor) are management-level roles that do not support ABAC conditions at this time. Similarly, User4 (Virtual Machine Contributor) is a compute management role and lacks the necessary data action permissions required for ABAC implementation. Only roles with specific data plane permissions (like blob read/write) enable the 'Conditions' tab in the Azure portal.

Community Comment Notes

Community consensus strongly favors Option C. As noted by user penatuna, testing in the Azure portal confirms that the Conditions tab is greyed out for Reader, Contributor, and VM Contributor, but active for Storage Blob Data Reader. Official Microsoft documentation also lists 'Storage Blob Data Reader' among the roles supporting ABAC conditions.

Official Reference

Exam Strategy

When studying for SC-300, memorize the specific built-in roles that support ABAC conditions. Focus on data plane roles related to Blob Storage, Data Lake Gen2, and Key Vault, as these are the primary candidates for ABAC questions.

Frequently Asked Questions

Does Contributor role support ABAC?

No, the Contributor role is a management role and does not support ABAC conditions. ABAC is currently limited to specific data plane roles.

Why is Virtual Machine Contributor wrong for ABAC?

Virtual Machine Contributor manages compute resources but lacks the specific data actions (like blob storage) required to enable ABAC conditions.

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide