Skip to content

Backfitting permissions from New-AzRoleAssignment (Failed) #125

Answered by DCMattyG
GeordieGuy asked this question in Q&A
Discussion options

You must be logged in to vote

Hi @GeordieGuy, thanks for reaching out on the discussions!

The "Global Admin" component only really comes into play when the script attempts to grant Admin Consent to the App Registrations. The issue you're running into appears to be that you don't have the appropriate permissions at the Tenant Root Group to assign "Reader" to the IPAM Engine App Registration (if I'm understanding your problem correctly).

We have a 2-part deployment option, where in the first part, a team within your organization can deploy the App Registrations on your behalf, and that will output a Parameters file you can feed into the second step where the Azure infrastructure is deployed.

Two Part Deployment:
Deploym…

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@Jtayta
Comment options

@DCMattyG
Comment options

Answer selected by GeordieGuy
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants