Andrew Mercer
on this page
    Azure RBAC
    
    ├── Role Definition          (set of permissions: Actions, NotActions, DataActions...)
    
    ├── Scope                    (Management Group / Subscription / Resource Group / Resource)
    
    └── Role Assignment          (binds a Role Definition + Scope to a Security Principal)
        
        └── Security Principal    (the "who" being granted access)
            
            ├── User
            
            ├── Group
            
            └── Service Principal
                
                ├── Application            (from an app registration; has an app object)
                ├── Managed Identity        (auto-created by Azure; no app object)
                   ├── System-Assigned     (1:1 with a resource, same lifecycle)
                   └── User-Assigned       (standalone resource, attach to many)
                ├── Legacy                  (pre-app-registration era apps)
                └── Social IdP              (external identity providers)