Practical cybersecurity from Northern Ireland
Glossary

Role-Based Access Control (RBAC)

Grants permissions based on a user's role within the organisation, rather than assigning access to each person individually.

Instead of deciding access on a person-by-person basis, RBAC groups permissions into roles — HR Manager, Finance Admin, IT Support — and assigns users to the role that matches their job. Change someone’s job and you change their role assignment; you don’t have to hunt down every individual permission they’ve accumulated over time.

RBAC is simpler to audit than assigning access one person at a time, which is why it’s the default starting point for most access control programmes, including in Microsoft Entra.

For finer-grained control than a role alone can provide — access decisions based on department, time of day, or resource sensitivity — RBAC is often paired with Conditional Access and, for privileged roles specifically, PIM.