Currently, I am working on establishing enterprise-scale landing zones for Cloud Adoption Framework in Azure.
Azure has a list of BuiltInRoles defined as mentioned in this article - https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles.
It is unclear to me which role should be assigned to which resource
Especially for the below Resources
- Management Groups
- Subscriptions
- Vnets
- Gateways,
- VMs
- Storage Accounts,
- SQL databases
Can you suggest what are all the Roles should be assigned while provisioning any of the above listed Resources?
