{"type":"video","version":"1.0","html":"<iframe src=\"https://www.loom.com/embed/67ff3f4d1392464f8f7163dcbd0927de\" frameborder=\"0\" width=\"1920\" height=\"1440\" webkitallowfullscreen mozallowfullscreen allowfullscreen></iframe>","height":1440,"width":1920,"provider_name":"Loom","provider_url":"https://www.loom.com","thumbnail_height":1440,"thumbnail_width":1920,"thumbnail_url":"https://cdn.loom.com/sessions/thumbnails/67ff3f4d1392464f8f7163dcbd0927de-93b9df7a44c9a8f8.gif","duration":614.48,"title":"Azure RBAC Least Privilege VM Access Lab","description":"This Loom demonstrates an Azure role-based access control lab that enforces least privilege for managing a VM. It describes modeling three jobs using built-in roles owner, virtual machine contributor, and reader, where the sysadmin can fully manage permissions, the support tech can start and stop but cannot delete or change access, and the auditor can view only. The Terraform setup scopes all role assignments to a single VM resource ID to minimize blast radius, uses Azure Blob Storage for backend state with a separate state key, and includes safety steps like requiring object IDs with no defaults and keeping real identity values out of source control. The author validates the live configuration with a script and then proves it by logging in as each user and showing the expected allowed or denied actions."}