WASdev / azure.liberty.aks

Apache License 2.0
2 stars 8 forks source link

Simplify wording even more regarding required role for UAMI #30

Closed edburns closed 2 years ago

edburns commented 2 years ago

Our current wording on the Basic blade regarding UAMI reads:

Select only one user-assigned managed identity that has (1) an Owner role or Contributor and User Access Administrator roles in the subscription, and (2) a Directory readers role in Azure AD.

@m-reza-rahman requests we temporarily suspend our respect for the principal of least privilege in the name of simplicity and change the wording to be:

Select only one user-assigned managed identity that has (1) the Owner role in the subscription, and (2) a Directory readers role in Azure AD.