Uppsats

A Comparative Study of RBAC and ABAC in Microsoft Entra : Differences in Authorization Granularity, Administration Complexity, and Policy Adaptability

Kandidat-uppsats

Karlstads universitet/Handelshögskolan (from 2013)

Publicerad: 2026

Språk: Engelska

Sammanfattning

Identity and Access Management (IAM) systems are critical components in modern cloud environments. Organizations must balance security, flexibility and administrative complexity when controlling access to resources. Within Microsoft Entra, Role-Based Access Control (RBAC) remains the dominant model, while Attribute-Based Access Control (ABAC) is increasingly discussed as a more flexible alternative. Despite extensive theoretical research on both models, there is limited empirical evidence comparing their practical behavior and implementation within this specific platform context. This study addresses that gap by conducting an empirical comparison of RBAC and ABAC within a Microsoft Entra-based environment. A Proof-of-Concept (PoC) application was designed and implemented, where both authorization models were applied under identical conditions. Four controlled test scenarios were developed to isolate key characteristics, including resource filtering, sensitivity constraints, ownership-based access and write operations. Authorization behavior was evaluated using measurable indicators such as access decision, visible resources and evaluation scope, enabling systematic comparison between the models. The results show that ABAC provides higher granularity and flexibility by enabling attribute-based, per-resource authorization decisions and supporting multi-attribute, context-dependent policies. In contrast, RBAC produces consistent and predictable access decisions based on role membership but requires additional roles to represent complex or dynamic access requirements. The study further shows that RBAC has lower initial implementation complexity, while ABAC introduces greater upfront complexity through policy design and attribute management. However, ABAC demonstrates improved adaptability, as access decisions automatically reflect changes in resource attributes, whereas RBAC requires manual updates to role assignments. The findings indicate that neither model is universally superior. RBAC is well suited for stable environments with clearly defined roles, while ABAC is more appropriate for dynamic and context-dependent scenarios. The study contributes empirical evidence to the problem domain and highlights the practical trade-offs between role-based and attribute-based authorization in Microsoft Entra.

Information

Lärosäte / institution
Karlstads universitet/Handelshögskolan (from 2013)
Publiceringsdatum
2026
Uppsatstyp
Kandidat-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.