Skip to content

Commit 0d424e8

Browse files
committed
clarifications
1 parent 4c0c38e commit 0d424e8

File tree

1 file changed

+13
-9
lines changed

1 file changed

+13
-9
lines changed

articles/search/search-get-started-rbac.md

Lines changed: 13 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -12,9 +12,9 @@ ms.date: 11/28/2024
1212

1313
# Quickstart: Connect without keys
1414

15-
Configure Azure AI Search to use Microsoft Entra ID authentication and roles. Connect from your local system, running Jupyter notebooks, or using a REST client.
15+
Configure Azure AI Search to use Microsoft Entra ID authentication and role-based access control (RBAC). Connect from your local system using your personal identity, using Jupyter notebooks or a REST client to interact with your search service.
1616

17-
If you stepped through other quickstarts that connect using API keys, this quickstart shows you how to switch to identity-based authentication so that you can avoid hard-coded API keys in your example code.
17+
If you stepped through other quickstarts that connect using API keys, this quickstart shows you how to switch to identity-based authentication so that you can avoid hard-coded keys in your example code.
1818

1919
## Prerequisites
2020

@@ -34,25 +34,25 @@ This step is necessary if you have more than one subscription or tenant.
3434

3535
1. Notice the subscription name and ID in **Overview** > **Essentials**.
3636

37-
1. Select the subscription name to view the parent management group (tenant ID).
37+
1. Select the subscription name to confirm the parent management group (tenant ID).
3838

3939
:::image type="content" source="media/search-get-started-rbac/select-subscription-name.png" lightbox="media/search-get-started-rbac/select-subscription-name.png" alt-text="Screenshot of the portal page providing the subscription name":::
4040

4141
1. Identify the active Azure subscription and tenant on your local device:
4242

4343
`az account show`
4444

45-
1. Set your Azure subscription to the subscription and tenant, and sign in to Azure.
45+
1. If the active subscription is different from the one used by Azure AI Search, change the subscription ID. Next, sign in to Azure using the same tenant ID as Azure AI Search.
4646

4747
`az account set --subscription <your-subscription-id>`
4848

4949
`az login --tenant <your-tenant-id>`
5050

51-
1. Check your tenant ID:
51+
1. Verify your tenant ID.
5252

5353
`az account show --query tenantId --output tsv`
5454

55-
## Step 2: Configure Azure AI Search for Microsoft Entra ID authentication
55+
## Step 2: Configure Azure AI Search for RBAC
5656

5757
1. Sign in to the [Azure portal](https://portal.azure.com) and navigate to your Azure AI Search service.
5858

@@ -72,14 +72,18 @@ This step is necessary if you have more than one subscription or tenant.
7272

7373
1. Select **+ Add** > **Add role assignment**.
7474

75-
1. Choose a role (Search Service Contributor, Search Index Data Contributor, Search Index Data Reader) and assign it to your Microsoft Entra user or group identity. These three roles provide the full set of permissions for creating, loading, and querying objects on Azure AI Search. For more information, see [Connect using roles](search-security-rbac.md).
75+
1. Choose a role (Search Service Contributor, Search Index Data Contributor, Search Index Data Reader) and assign it to your Microsoft Entra user or group identity.
76+
77+
Repeat for each role.
78+
79+
You need all three roles for creating, loading, and querying objects on Azure AI Search. For more information, see [Connect using roles](search-security-rbac.md).
7680

7781
> [!TIP]
78-
> Later, if you get authentication failure errors, recheck the settings in this section. There could be policies set at the subcription or resource group level that enforce specific security settings.
82+
> Later, if you get authentication failure errors, recheck the settings in this section. There could be policies at the subscription or resource group level that override any API settings you specify.
7983
8084
## Step 3: Connect from your local system
8185

82-
If you didn't sign in to Azure with an `az login` command, do so now.
86+
If you haven't yet signed in to Azure, do so now with an `az login` command.
8387

8488
### Using Python and Jupyter notebooks
8589

0 commit comments

Comments
 (0)