Skip to content

Commit d515673

Browse files
committed
Update to specify read pemission
1 parent ffa7cde commit d515673

1 file changed

Lines changed: 9 additions & 5 deletions

File tree

docs/sql-server/azure-arc/prerequisites.md

Lines changed: 9 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -32,19 +32,23 @@ Before you can Arc-enable an instance of [!INCLUDE [ssnoversion-md](../../includ
3232

3333
To [Connect SQL Servers on Azure Arc-enabled servers at scale using Azure policy](connect-at-scale-policy.md):
3434

35+
- The service principal requires read permission on the subscription.
36+
3537
- The installation account requires:
3638

3739
- [`User Access Administrator`](/azure/role-based-access-control/built-in-roles#user-access-administrator) role assignment is required in the subscription if you are creating a *new* system assigned managed identity.
3840
- [`Resource Policy Contributor`](/azure/role-based-access-control/built-in-roles#resource-policy-contributor) role assignment for the scope that you're targeting. The scope may be either subscription or resource group.
3941

42+
For all the other onboarding methods:
43+
4044
- The service principal requires read permission on the subscription.
4145

42-
For all the other onboarding methods, user or service principal must have permissions in the Azure resource group to complete the task. Specifically:
46+
- User or service principal must have permissions in the Azure resource group to complete the task. Specifically:
4347

44-
- [`Azure Connected Machine Onboarding`](/azure/role-based-access-control/built-in-roles#azure-connected-machine-onboarding) role
45-
- `Microsoft.AzureArcData/register/action`
46-
- `Microsoft.HybridCompute/machines/extensions/read`
47-
- `Microsoft.HybridCompute/machines/extensions/write`
48+
- [`Azure Connected Machine Onboarding`](/azure/role-based-access-control/built-in-roles#azure-connected-machine-onboarding) role
49+
- `Microsoft.AzureArcData/register/action`
50+
- `Microsoft.HybridCompute/machines/extensions/read`
51+
- `Microsoft.HybridCompute/machines/extensions/write`
4852

4953
Users can be assigned to built-in roles that have these permissions, for example [Contributor](/azure/role-based-access-control/built-in-roles#contributor) or [Owner](/azure/role-based-access-control/built-in-roles#owner). For more information, see [Assign Azure roles using the Azure portal](/azure/role-based-access-control/role-assignments-portal).
5054

0 commit comments

Comments
 (0)