Clarify Custom Role Definition for AzureDevopsInfrastructure Principal #14134
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The docs are incomplete on permissions needed in a custom role, as well as being ambigious as to whether the
Reader
role is needed in addition to the custom role or notSolve the ambiguity by including the
Microsoft.Network/virtualNetworks/*/read
action in the custom role definition, and making clear that is an alternative to the two built in rolesAdded a missing permission required to delete a managed devops pool
Microsoft.Network/virtualNetworks/subnets/serviceAssociationLinks/delete
action required to delete a managed devops pool