azure-devops-docs icon indicating copy to clipboard operation
azure-devops-docs copied to clipboard

Clarify Custom Role Definition for AzureDevopsInfrastructure Principal

Open afscrome opened this issue 6 months ago • 2 comments

The docs are incomplete on permissions needed in a custom role, as well as being ambigious as to whether the Reader role is needed in addition to the custom role or not

Solve the ambiguity by including the Microsoft.Network/virtualNetworks/*/read action in the custom role definition, and making clear that is an alternative to the two built in roles

Added a missing permission required to delete a managed devops pool Microsoft.Network/virtualNetworks/subnets/serviceAssociationLinks/delete action required to delete a managed devops pool

afscrome avatar Aug 30 '24 18:08 afscrome