cykreng / Enterprise-Scale-AppService

8 stars 9 forks source link

SP creation - review privileges and use of sdk-auth #74

Open ahmedsza opened 2 years ago

ahmedsza commented 2 years ago

The SP guidance az ad sp create-for-rbac 1) generates a warning that sdk-auth will be deprecated 2) grants contributor permission to the entire sub. This might be overkill but the current implementation seems like it needs it. Many customers will have admins who create resource groups and then grant the min permissions to the RG.