azure-docs icon indicating copy to clipboard operation
azure-docs copied to clipboard

Statement on inherited readability

Open tyson-trust opened this issue 1 year ago • 2 comments

Where it states

All Policy objects, including definitions, initiatives, and assignments, will be readable to all roles over its scope. For example, a Policy assignment scoped to an Azure subscription will be readable by all role holders at the subscription scope and below.

This is correct for definitions and initiatives but does NOT appear to be correct for assignments.

If I assign a identity a role at a resource group level, that identity is able to access details on initiatives applied to the subscription the resource group is in, it is also able to look at any customer definitions at either a management group or a subscription scope however if I execute the PolicyAssignments_ListForResourceGroup, PolicyAssignments_ListForResource or PolicyAssignments_List apis then I just get a 200 response with

{
    "value": []
}

I have to grant the role the Microsoft.Authorization/policyAssignments/read action at the appropriate scope to be able to view the policy assignment.


Document Details

Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.

tyson-trust avatar Jun 02 '23 02:06 tyson-trust

@tyson-trust Thanks for your feedback! We will investigate and update as appropriate.

SaibabaBalapur-MSFT avatar Jun 02 '23 05:06 SaibabaBalapur-MSFT

#reassign:davidsmatlak

davidsmatlak avatar Jun 03 '23 01:06 davidsmatlak

I created an internal work item to review the article and I'll post a comment after the article is reviewed. I'm closing this issue.

#please-close

davidsmatlak avatar Aug 03 '23 00:08 davidsmatlak