Uppsats
A Comparative Study of RBAC and ABAC in Microsoft Entra : Differences in Authorization Granularity, Administration Complexity, and Policy Adaptability
Kandidat-uppsats
Karlstads universitet/Handelshögskolan (from 2013)
Publicerad: 2026
Språk: Engelska
Nyckelord
klicka för att sökaSammanfattning
Identity and Access Management (IAM) systems are critical components in modern cloud environments. Organizations must balance security, flexibility and administrative complexity when controlling access to resources. Within Microsoft Entra, Role-Based Access Control (RBAC) remains the dominant model, while Attribute-Based Access Control (ABAC) is increasingly discussed as a more flexible alternative. Despite extensive theoretical research on both models, there is limited empirical evidence comparing their practical behavior and implementation within this specific platform context. This study addresses that gap by conducting an empirical comparison of RBAC and ABAC within a Microsoft Entra-based environment. A Proof-of-Concept (PoC) application was designed and implemented, where both authorization models were applied under identical conditions. Four controlled test scenarios were developed to isolate key characteristics, including resource filtering, sensitivity constraints, ownership-based access and write operations. Authorization behavior was evaluated using measurable indicators such as access decision, visible resources and evaluation scope, enabling systematic comparison between the models. The results show that ABAC provides higher granularity and flexibility by enabling attribute-based, per-resource authorization decisions and supporting multi-attribute, context-dependent policies. In contrast, RBAC produces consistent and predictable access decisions based on role membership but requires additional roles to represent complex or dynamic access requirements. The study further shows that RBAC has lower initial implementation complexity, while ABAC introduces greater upfront complexity through policy design and attribute management. However, ABAC demonstrates improved adaptability, as access decisions automatically reflect changes in resource attributes, whereas RBAC requires manual updates to role assignments. The findings indicate that neither model is universally superior. RBAC is well suited for stable environments with clearly defined roles, while ABAC is more appropriate for dynamic and context-dependent scenarios. The study contributes empirical evidence to the problem domain and highlights the practical trade-offs between role-based and attribute-based authorization in Microsoft Entra.
Information
- Författare
- Christiansson, Melker
- Lärosäte / institution
- Karlstads universitet/Handelshögskolan (from 2013)
- Publiceringsdatum
- 2026
- Uppsatstyp
- Kandidat-uppsats
- Språk
- Engelska
Utforska vidare
Liknande uppsatser
Uppsatser med liknande ämnen och nyckelord.
Kandidat-uppsats, Jönköping University/JTH, Avdelningen för datateknik och informatik
Nasan, Awaz, Alsharif, Anas
Publicerad: 2026
Kandidat-uppsats, KTH/Hälsoinformatik och logistik
Tadesse, Bemnet
Publicerad: 2026
Kandidat-uppsats, Mittuniversitetet/Institutionen för data- och elektroteknik (2023-)
Hellzén, Philip
Publicerad: 2026
Yrkesexamen på avancerad nivå, Uppsala universitet/Avdelningen för systemteknik
Bertilsson, Sanna
Publicerad: 2026