-
Notifications
You must be signed in to change notification settings - Fork 42
Permissions
This module uses two providers, azapi
and azurerm
. We recommend that you use the same identity for both providers.
This sub-module manages the following resources:
The identity used must have permission to:
- Create subscriptions using the
Microsoft.Subscription/aliases
resource. See the documentation for details.
Note: The following process explains how to assign EA roles to SPNs.
- Manage the subscription's management group using the
Microsoft.Management/managementGroups
resource. For a detailed explanation of the permissions required, see the documentation.
Note: the identity that creates the subscription will have
Owner
permissions assigned by default. If you instead supply an existing subscription id, you must ensure that the identity of the provider has theOwner
permissions assigned.
This sub-module manages the following resources using the AzAPI provider:
Microsoft.Network/virtualHubs/hubVirtualNetworkConnections
Microsoft.Network/virtualNetworks/virtualNetworkPeerings
Microsoft.Network/virtualNetworks
Microsoft.Resources/resourceGroups
These resources are deployed into the new or the supplied subscription. The identity of the AzAPI provider must have permission to create these resources.
This sub-module manages the following resources using the AzureRM provider:
The role assignments are deployed into either the new or the supplied subscription, at subscription or child scopes.
The identity of the AzureRM provider must have permission to create these resources, typically this means having the Owner
or User Access Administrator
roles.
This wiki is being actively developed
If you discover any documentation bugs or would like to request new content, please raise them as an issue or feel free to contribute to the wiki via a pull request.
The wiki docs are located in the repository in the docs/wiki/
folder.