OnCallReady

Azure I: CLI, Identity & Data Planes: interview questions

The question you are most likely to get for each topic, a model answer, and what else comes up. From chapter 22 of the course.

Explain the Azure resource hierarchy and how RBAC permissions flow through it. Mid

Entra ID tenant      who exists: users, groups, apps, identities
 └─ management group optional folders of subscriptions
     └─ subscription billing + RBAC boundary (dev and prod separate)
         └─ resource group  resources that live and die together
             └─ resource    a vault, a VNet, a cluster

A role assignment is three things: who (a principal, by object id), what (a role definition: a list of actions and dataActions) and where (a scope: one of the boxes above).

Least privilege = the smallest role at the smallest scope, granted to groups.

Also asked: What is the difference between authentication and authorisation in Azure? · Why can a subscription Owner not read a secret from a Key Vault? · How should an application running on Azure authenticate to other Azure services?

What is the difference between the Azure control plane and the data plane? Give examples. Mid

Analogy: the control plane is the building's management office (build the safe, hand out keys); the data plane is opening the safe.

Why it matters: being Owner of the subscription lets you create and configure a vault, but reading a secret in it is Forbidden until you hold a data-plane role on the vault. Half of all Azure "Forbidden" surprises are this split.

Related habit: az account show before anything that writes, or --subscription in scripts.

Also asked: How do you make sure a CLI command runs against the right Azure subscription? · A script fails with AuthorizationFailed. What does the error tell you? · How do you sign in to Azure from a server that has no browser?

Learn it: 22.1 What `az` actually talks to

How do you get a single value from an az command into a shell variable reliably? Mid

Pair --query with -o tsv:

KV_ID=$(az keyvault show -n kv-shop-prod --query id -o tsv)
az role assignment list --scope "$KV_ID" -o table

Why each format matters:

--query runs inside the CLI, so it works the same in bash, PowerShell or a pipeline without jq; | jq -r is fine when jq is there or you need to aggregate.

Also asked: What are the trade-offs between az --query and piping to jq? · Why is a field you expect missing from az's table output? · How would you write a reliable script that loops over Azure resources and acts on each?

Learn it: 22.3 Output formats: json, table, tsv, yaml

How would you list the names of all resource groups in one region with the Azure CLI, and what mistakes do people make with --query? Mid

az group list --query "[?location=='westeurope'].name" -o tsv

[?condition] filters the list, .name projects each element, -o tsv prints bare names.

The silent mistakes (no error, just no output):

az aks nodepool list -g rg-oncall-lab --cluster-name aks-sysop --query '[?count > `2`].name' -o tsv

For your own table: --query "[].{Name:name, Count:count}" -o table - the way to get nested fields into a table. JMESPath cannot group or sum; use -o tsv | awk or jq for that.

Also asked: Explain the difference between [?filter].name[0] and [?filter].name | [0] in JMESPath. · How do you show nested fields of az output in a table? · When would you use jq or awk instead of --query?

Learn it: 22.4 JMESPath: --query properly

What is a service principal, and how is it different from an app registration? Mid

Job description vs employee badge: permissions go on the badge. Three IDs, three uses: appId to log in (az login --service-principal -u <appId>), SP object ID for RBAC, tenantId for the directory. An assignment made with --assignee-object-id <appId> points at nothing.

Credentials, best last: a client secret (leaks, expires, shown once by az ad sp create-for-rbac), a certificate, a federated credential - Entra ID trusts an OIDC token from another issuer (a GitHub workflow, a cluster), so there is no secret at all.

Sign-in errors carry an AADSTS code; AADSTS7000215 usually means someone copied the secret's ID instead of its value.

Also asked: How should a deploy job running outside Azure authenticate to Azure? · What is the difference between authentication and authorisation in Azure? · What is the difference between Entra roles and Azure roles?

Learn it: 22.8 Entra ID: users, apps, service principals

What is a managed identity, and when do you use system-assigned versus user-assigned? Mid

A managed identity is a service principal whose credential Azure creates, stores and rotates. Code on Azure compute asks the Instance Metadata Service (169.254.169.254, reachable only from that machine) for a token - the SDKs' DefaultAzureCredential does it - so there is no secret in any config.

Rule most platform teams use: user-assigned for anything Terraform manages; system-assigned for a one-off resource. clientId says which identity the workload wants; principalId is what RBAC is granted to.

On Azure, managed identity always; outside Azure, a federated credential. And never grant app access to a cluster's kubelet identity - every pod on every node shares it; pods get their own through workload identity.

Also asked: How does workload identity let a pod authenticate to Azure without a secret? · When would you use a service principal instead of a managed identity? · Why should you not give the cluster's kubelet identity access to application secrets?

Learn it: 22.9 Managed identities: system-assigned vs user-assigned

What are the parts of an Azure role assignment, and how do you work out what someone can actually do? Mid

Three parts: who (a principal's object id), what (a role definition), where (a scope: management group, subscription, resource group, resource).

A role definition lists actions (control plane, ARM) and dataActions (data inside a service: getSecret, blob read). notActions only subtract within that role - not a deny. Owner and Contributor have no dataActions; Contributor also cannot write Microsoft.Authorization.

Effective access = the union of every assignment at the scope and above (inheritance flows down only). Nothing "more specific wins"; only a deny assignment subtracts.

Checking it without the classic trap:

Least privilege: data roles for data, smallest scope, Terraform owns the assignments.

Also asked: Why can a subscription Owner not read secrets from a Key Vault? · Why is User Access Administrator considered as powerful as Owner? · How do you implement least privilege with Azure RBAC?

Learn it: 22.13 Azure RBAC: roles, scopes, inheritance

Why should you assign Azure roles to groups rather than users, and how do you handle privileged access? Mid

Groups: grant the role to a security group once, then manage membership. Onboarding = add to groups; offboarding = remove, and every role goes at once. Access reviews read memberships instead of hundreds of assignments, and you stay under the per-subscription assignment limit. Checking a person means checking their groups too: az role assignment list --assignee <id> --all --include-groups. A new member needs a new token - groups travel as claims in it.

Privileged access - just in time: with PIM (Privileged Identity Management) dangerous roles are eligible, not standing. You activate Owner on prod for a few hours, with a justification, MFA and optionally approval; it is logged and expires. "Nobody has standing Owner in production."

Narrow roles: a custom role when built-ins are too broad - explicit actions (found from the AuthorizationFailed error or az provider operation show), narrow AssignableScopes, in Terraform. And conditions: Role Based Access Control Administrator limited to assigning specific roles lets a pipeline grant access without being able to make itself Owner.

Also asked: What is Privileged Identity Management and how does it improve security? · When would you write a custom role, and how do you find the actions it needs? · How do you let a Terraform pipeline create role assignments without letting it escalate its own privileges?

Learn it: 22.18 Groups, custom roles and just-in-time access

An application gets 403 when reading a Key Vault secret. How do you troubleshoot it? Mid

Read the error - it names everything:

The usual fix: Key Vault Secrets User for that identity's object id, scoped to the vault (or one secret). Traps: Owner and Key Vault Contributor have no data access, and Key Vault Reader reads metadata only, never values - read the dataActions, not the name. A brand-new assignment can take minutes to propagate.

If the identity never gets a token at all, it is an AADSTS error, not a 403.

Also asked: What is Azure Key Vault used for, and what can it store? · What do soft delete and purge protection protect you from? · Compare Key Vault access policies with the Azure RBAC permission model.

Learn it: 22.23 Key Vault: two permission models, one data plane

How do you get secrets from Azure Key Vault into a pod without storing them in git? Mid

Three parts, nothing secret anywhere in git or the image:

  1. An identity for the pod - workload identity: a user-assigned identity with a federated credential for the pod's ServiceAccount (system:serviceaccount:<ns>:<sa>).
  2. A role on the vault - Key Vault Secrets User for that identity, scoped to the vault.
  3. A mount - the Secrets Store CSI driver (an add-on): a SecretProviderClass in the app's namespace names the vault, the identity's client ID and the secrets; the pod mounts a CSI volume using it. At pod start the provider authenticates as the pod's identity, reads the secrets and writes them as files in a tmpfs: /mnt/secrets/orders-db-password.

Optionally secretObjects syncs them into a Kubernetes Secret for env vars - but that is only base64 in etcd, so files are the better default.

When it fails the pod stays in ContainerCreating and the reason is a FailedMount event (kubectl describe pod), embedding the Key Vault error: 403 = role, AADSTS70021 = federated credential mismatch, SecretNotFound = typo. Rotation updates the files, not a running app's environment.

Also asked: A pod using the Key Vault CSI driver is stuck in ContainerCreating. How do you find out why? · What are the trade-offs between mounting secrets as files and exposing them as environment variables? · What happens to a running app when a secret in Key Vault is rotated?

Learn it: 22.27 From Key Vault into a pod: the Secrets Store CSI driver

What are the ways to authenticate to Azure Blob Storage, and which do you prefer? Mid

Watch the CLI: with no credentials, az storage blob commands quietly fetch the account key ("we will query for account key") - root. Use --auth-mode login; as Owner without a data role you then get a permissions error, because Owner is control plane.

To make Entra ID the only way in: data roles first, then az storage account update --allow-shared-key-access false (KeyBasedAuthenticationNotPermitted afterwards) - checking first what still uses keys or SAS. Plus allowBlobPublicAccess false.

Also asked: How would you secure the storage account that holds Terraform state? · Why is Contributor on a storage account effectively full data access? · What do the redundancy options LRS, ZRS and GRS mean?

Learn it: 22.29 Storage accounts, blobs, and who is allowed in

What is the difference between Azure Disks and Azure Files for Kubernetes persistent volumes? Mid

Ask a disk class for ReadWriteMany and the PVC stays Pending with ProvisioningFailed - the request is impossible. So three pods sharing a volume = Azure Files, or better, redesign to object storage (blobs).

Housekeeping: classes with Retain leave disks behind when the PVC is deleted - az disk list --query "[?diskState=='Unattached']" finds them, and the created-for-pvc-name tag says whose they were.

Also asked: A pod is stuck in ContainerCreating after being rescheduled to a node in another zone. Why? · How do you find and clean up orphaned disks safely? · Three pods need a shared volume on a Kubernetes cluster in Azure. What do you use and why?

Learn it: 22.31 Managed disks (RWO) and Azure Files (RWX) for Kubernetes

Practise these answers with flashcards and labs Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.