Back to Skills

azure-rbac

Helps users find the right Azure RBAC role for an identity with least privilege access, then generate CLI commands and Bicep code to assign it. Also provides guidance on permissions required to grant roles. WHEN: bicep for role assignment, what role should I assign, least privilege role, RBAC role for, role to read blobs, role for managed identity, custom role definition, assign role to identity, what role do I need to grant access, permissions to assign roles.

181stars119forksUpdated 4/8/2026

Security Assessment

Safe(100/100)
Security Score100/100

About azure-rbac

The azure-rbac skill is designed to simplify the process of assigning Azure Role-Based Access Control (RBAC) roles to identities while ensuring least privilege access. It addresses the common challenge of determining the minimal set of permissions necessary for an identity to perform specific tasks, and then generating the appropriate Azure CLI commands or Bicep code to enforce those permissions. By guiding users to the most appropriate built-in or custom roles, this skill helps prevent over-permissioning, which is a critical security concern in cloud environments.

This skill provides several key capabilities. It can identify the minimal built-in role that matches the desired permissions for an identity, and if no suitable role exists, it facilitates the creation of a custom role definition. It also generates the necessary CLI commands to assign the selected role and provides Bicep code snippets for infrastructure-as-code scenarios. Additionally, it offers guidance on the permissions required to assign roles, ensuring users understand the prerequisites, such as needing the User Access Administrator, Owner, or a custom role with `Microsoft.Authorization/roleAssignments/write` permissions. These features streamline RBAC management and reduce the risk of misconfiguration.

The azure-rbac skill is particularly useful for cloud administrators, DevOps engineers, and developers who manage Azure resources and need to enforce secure, least-privilege access. Common use cases include determining which role to assign for reading storage blobs, assigning roles to managed identities, creating custom roles with precise permissions, and automating role assignments through CLI or Bicep templates. By providing clear guidance and automation, this skill supports efficient and secure role management in enterprise and project-level Azure environments.

FAQ

How do I determine the correct RBAC role for an identity?

Use the skill to analyze the permissions required for the identity's tasks. It will suggest the minimal built-in role or guide you in creating a custom role if needed.

Can I generate both CLI commands and Bicep code with this skill?

Yes, the skill can produce Azure CLI commands for role assignment and Bicep code snippets for infrastructure-as-code deployments.

What permissions are required to assign roles?

To assign RBAC roles, you need a role that includes the `Microsoft.Authorization/roleAssignments/write` permission, such as User Access Administrator, Owner, or a custom role with the same permission.

Is this skill suitable for custom role creation?

Yes, if no built-in role meets the desired permissions, the skill guides you in generating a custom role definition with the necessary access.

Who should use this skill?

Cloud administrators, DevOps engineers, and developers managing Azure resources who need to enforce least-privilege access and automate role assignments will benefit from this skill.

Install azure-rbac

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill