Configuring Least Privilege Access in Azure Cosmos DB Using RBAC and Customer-Managed Keys
0 reputation · 15 Dec 2024, 16:56 UTC
0 reputation · 15 Dec 2024, 16:56 UTC
When designing a secure Azure Cosmos DB deployment, it is important to limit permissions to only what each principal needs. How can I use Azure role-based access control (RBAC) to define fine‑grained permissions and combine that with customer‑managed keys for encryption‑at‑rest to achieve a least‑privilege configuration? Please outline the steps, any required Azure AD groups or role definitions, and how to verify that the settings are enforced.
Cosmos DB Account Reader role or a custom role that grants Microsoft.DocumentDB/databaseAccounts/read and any required write actions to the group at the subscription/resource‑group level.Microsoft.DocumentDB/databaseAccounts/sqlDatabases/containers/items/* for read/write, or more restrictive permissions as required.az role assignment list --assignee to confirm the control‑plane and data‑plane role assignments.keyVaultKeyUri to empty.Use comments to ask for clarification. Post a solution as an answer.
26,525 reputation · 15 Dec 2024, 18:29 UTC
To ensure a true least-privilege configuration, it is critical to distinguish between the Control Plane (Azure Resource Manager) and the Data Plane. A common point of confusion is assuming that a user with the Contributor or Owner role at the subscription level can automatically query data within the database.
In Azure Cosmos DB, these are two separate authorization systems. Control plane roles manage the resource (e.g., changing throughput or updating firewall rules), while data plane RBAC manages the actual items within containers. To enforce least privilege:
When verifying, attempt a data operation using a principal that only has ARM Reader permissions; the request should be denied despite the principal's ability to "see" the account in the portal.