◆ Microsoft Azure

Manage Azure RBAC roles

This is real work, not a feature someone invented — it comes from real job ads and real questions people asked. Below are four ready AI prompts: get it done, make it easy for the next person to say yes to, work out the right move when you are stuck, and stop it coming back.

4prompts

The same task, four prompts

today's deadline · the next reviewer · the stuck moment · the pattern
AExecute — do the immediate taskGrant Maria Rodriguez, who is the new project manager, 'Contributor' access to the…+
Grant Maria Rodriguez, who is the new project manager, 'Contributor' access to the 'ProjectAlpha' resource group. She needs to be able to deploy resources there by this afternoon for her team's sprint. Ensure she can't accidentally delete anything critical.
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
BImprove — make it easier to acceptBefore we onboard the new development team, refine the RBAC for the 'DevEnvironment'…+
Before we onboard the new development team, refine the RBAC for the 'DevEnvironment' subscription. I need to ensure developers can deploy and manage their own resources but are strictly prevented from modifying networking configurations or creating new service principals. Also, implement a policy that flags any attempts to assign 'Owner' roles outside of a specific security group. This needs to be secure and scalable.
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
CDecide — diagnose the stuck momentJohn from the marketing team just created a new storage account in the 'Production' resource…+
John from the marketing team just created a new storage account in the 'Production' resource group.
John from the marketing team just created a new storage account in the 'Production' resource group, which he shouldn't have access to. I thought I had locked down production environments, but clearly, there's a loophole. He's asking why he can't access it now, and I can't tell him I messed up the permissions. The security audit is next week. What's the most common misconfiguration that allows unintended resource creation, and what's the immediate best step to revoke his specific ability without impacting other legitimate users?
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
DBecome — change the patternI keep getting ad-hoc requests for permissions that don't align with our security policies,…+
I keep getting ad-hoc requests for permissions that don't align with our security policies.
I keep getting ad-hoc requests for permissions that don't align with our security policies, often for 'temporary' access or broad roles. Each time, I have to explain why it's not allowed or find a workaround, which feels like I'm constantly fighting against the tide. This leads to frustration for users and delays. What habit should I change to proactively guide users towards appropriate roles and educate them on our security posture, perhaps by publishing clear role definitions or automating common access requests?
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?

Questions people actually ask

honest answers, no sign-up

Every task here was seen in the real world. Someone doing the job named it, a real job ad asked for it, or a lot of people asked about it online.

If nothing real showed a task, it is not on the page. That is the whole rule.

They are the same job approached four ways, because what you need depends on where you are.

Get it done today. Make it easy for the next person to say yes to. Work out the right move when you are stuck. Learn the pattern so the job stops coming back.

For most of these jobs it can carry the heavy thinking - draft it, sort it, check it, rehearse it with you.

It cannot sit in your chair, take the blame when a number is wrong, or notice what nobody wrote down. Let it do the first 80%. Keep the last 20% that is truly yours.

No. Copy any prompt and paste it into the AI you already use. No account, no score, no wall in the way.

Any of them. The prompts describe the work rather than naming a product, so they are not tied to one assistant.

That is also why they keep working when you switch.

Change it freely. Every prompt is a starting line, not a rule.

Put in your real numbers, your real names and your real deadline. The more you make it yours, the better the answer comes back.

The tasks come from real job ads, published job data and the questions people ask in public forums.

The steps come from Microsoft Azure's own documentation, with practitioner sources for the traps the manual does not mention.

Push once. Ask it to sharpen the weakest part and to say what it assumed.

Most wrong answers come from a missing detail rather than a bad prompt - tell it the thing it could not know.