How can I assign granular RBAC rights to Defender EASM Azure Resource
When creating a Defender EASM Resource in Azure, there is no possibility to granularly assign RBAC Roles to this resource. In the Defender EASM Portal the "IAM" Section is missing for role assignment. However in order to create the resource you…
azure owner roles issue
Hi Team, accidentally i was deleted my owner role attached to the my subscription . and now i am unable to perform operations in my account. could you please help me on this issue
Access control (IAM) Issue - Creating is greyed out
I am owner of a MS Action Pack Subscription. I cannot find out why i am not able to create role assignents in Access control (IAM) anymore. I stuck in the last menu. The create button is greyed out.
How to use Azure C# SDK to retriever filtered role assignments
I'm starting to feel like Azure C# SDK does not provide a way for me to list all role assignments a user has been assigned directly or indirectly assigned at a given scope (e.g. subscription). I know this is supported via the underlying REST API and…
Azure Service Health for Subscription ID
Hello, We got a following mail from [azure-noreply@microsoft.com] to some.body@some.hidden.company.com. But we dont have this Subscription ID someidid-****-****-81ef-hiddenhidden in our Azure account. Can you please help us how can we find the this …
Can't Access Sandbox
AADSTS500200: User account [Mod Removed - PII] is a personal Microsoft account. Personal Microsoft accounts are not supported for this application unless explicitly invited to an organization. Try signing out and signing back in with an organizational…
How to control access to a folder in ADLS gen2 container while Storage account IAMs are in action
Hi, I have a synapse pipeline that saves an output file in a folder (ex: salary) in an ADLS container (ex: employee). Now Mr. X wants the data saved in the folder to be accessible only to him but storage account level IAMs have already given access to…
Issue with roles and admin assignments
There was an issue with the roles and admins assignments. The assigned users were 14 members and Im able to see the assigned users as 15. What was the issue. Is the group name also added into the assigned users count.
How to apply roleAssignment write permissions to an application registration
Hey, i have an application registration to grant a terraform pipeline access to azure. The application registration has the contributor role on subscription scope. But Terraform now needs to be able to asign roles inside a resource group that was created…
AuthorizationFailed: Unable to Delete Role Assignment Due to ABAC Condition in Pay-As-You-Go Subscription 26049fd6-7b85-4142-8060-b88930cb8cec
I am writing to request your assistance with a critical issue I am facing in my Pay-As-You-Go subscription. I am encountering an AuthorizationFailed error while attempting to delete a role assignment. Despite having the Owner role for the subscription,…
Active directory Integration with RBAC for Azure CosmosDB with Mongo API
Planning to create RBAC for Azure Cosmos DB with Mongo API, is Active directory user integration is possible
Is there a way to copy all the IAM permissions on all resources from one account to another
we want to migrate a few accounts to having a separate account to access resources in Azure. Is there a way to copy all IAM Access controls for an account to another account?
I cannot access the azure portal with which I have Microsoft for Startups credits
When I try to access my azure portal with which I have Microsoft for Startup credits, I am getting following error. is there a way for you guys to fix this for me? { "sessionId": "31df0e0edbc74f8eabfb72d924bc227b", …
Using Git commands with Service Principal authentication.
I have been granted service principal access to my Azure DevOps repository. Below is the script I'm using: $resource="499b84ac-1321-427f-aa17-267ca6975798" $TenantId=" " $ClientId=" " $ClientSecret=" " $TokenUri =…
How can we give a permission to users non- downloaded document files and non- printable in Azure active directory.
How can we give a permission to users non- downloaded document files and non- printable in Azure active directory?
I can get permission to create the resources even i am the admin and i have the global control
i cant get access even i am the admin
Tag management on Azure
For a client I am attempting to build a tag manager role that allows only changing of tags on resources (add/remove/change from existing subscription tags), without being able to create new tags on the subscription. However, with the permissions set as…
How to authorize Entra ID apps as “apps” instead of “service principals
I registered my app through “Entra ID” for integration with New Relic. I granted the apps registered with the subscriptions to be viewed. Then, in the access control list, it was registered as a “service principal” instead of an “app”. How can I register…
Need MFA reset for Tenant Admin
Hi Team, Need your help in resetting the MFA for one of the Tenant admins in Azure portal. Kindly let me know the steps to do the same.
Azure IAM Role
Hello, I assign a user as network contributor and as reader, but why this user is able to doing write operation such as create VM, turn off the VM etc?