Skip to content

Commit 065ce5c

Browse files
Update manage-with-azure-rbac.md
Updated permissions for start and stop
1 parent 18f32c2 commit 065ce5c

File tree

1 file changed

+132
-0
lines changed

1 file changed

+132
-0
lines changed

articles/sap/center-sap-solutions/manage-with-azure-rbac.md

Lines changed: 132 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -300,6 +300,138 @@ To stop the SAP system from a VIS resource, a *user* and *user-assigned managed
300300
| `Microsoft.Compute/virtualMachines/extensions/write` |
301301
| `Microsoft.Compute/virtualMachines/instanceView/read` |
302302

303+
## Start SAP Central services instance
304+
To start the SAP Central services instance from a VIS resource, a *user* and *user-assigned managed identity* requires the following role or permissions.
305+
306+
| Built-in roles for *users* |
307+
| ------------------------- |
308+
| **Azure Center for SAP solutions administrator** |
309+
310+
| Minimum permissions for *users* |
311+
| ------------------------------- |
312+
| `Microsoft.Workloads/sapVirtualInstances/centralInstances/start/action` |
313+
314+
| Built-in roles for *user-assigned managed identities* |
315+
| ---------------------------------------------------- |
316+
| **Azure Center for SAP solutions service role** |
317+
318+
| Minimum permissions for *user-assigned managed identities* |
319+
| ---------------------------------------------------------- |
320+
| `Microsoft.Compute/virtualMachines/read` |
321+
| `Microsoft.Compute/virtualMachines/extensions/read` |
322+
| `Microsoft.Compute/virtualMachines/extensions/write` |
323+
| `Microsoft.Compute/virtualMachines/instanceView/read` |
324+
325+
## Stop SAP Central services instance
326+
To stop the SAP Central services instance from a VIS resource, a *user* and *user-assigned managed identity* requires the following role or permissions.
327+
328+
| Built-in roles for *users* |
329+
| ------------------------- |
330+
| **Azure Center for SAP solutions administrator** |
331+
332+
| Minimum permissions for *users* |
333+
| ------------------------------- |
334+
| `Microsoft.Workloads/sapVirtualInstances/centralInstances/stop/action` |
335+
336+
| Built-in roles for *user-assigned managed identities* |
337+
| ---------------------------------------------------- |
338+
| **Azure Center for SAP solutions service role** |
339+
340+
| Minimum permissions for *user-assigned managed identities* |
341+
| ---------------------------------------------------------- |
342+
| `Microsoft.Compute/virtualMachines/read` |
343+
| `Microsoft.Compute/virtualMachines/extensions/read` |
344+
| `Microsoft.Compute/virtualMachines/extensions/write` |
345+
| `Microsoft.Compute/virtualMachines/instanceView/read` |
346+
347+
## Start SAP Application server instance
348+
To start the SAP Application server instance from a VIS resource, a *user* and *user-assigned managed identity* requires the following role or permissions.
349+
350+
| Built-in roles for *users* |
351+
| ------------------------- |
352+
| **Azure Center for SAP solutions administrator** |
353+
354+
| Minimum permissions for *users* |
355+
| ------------------------------- |
356+
| `Microsoft.Workloads/sapVirtualInstances/applicationInstances/start/action` |
357+
358+
| Built-in roles for *user-assigned managed identities* |
359+
| ---------------------------------------------------- |
360+
| **Azure Center for SAP solutions service role** |
361+
362+
| Minimum permissions for *user-assigned managed identities* |
363+
| ---------------------------------------------------------- |
364+
| `Microsoft.Compute/virtualMachines/read` |
365+
| `Microsoft.Compute/virtualMachines/extensions/read` |
366+
| `Microsoft.Compute/virtualMachines/extensions/write` |
367+
| `Microsoft.Compute/virtualMachines/instanceView/read` |
368+
369+
## Stop SAP Application server instance
370+
To stop the SAP Application server instance from a VIS resource, a *user* and *user-assigned managed identity* requires the following role or permissions.
371+
372+
| Built-in roles for *users* |
373+
| ------------------------- |
374+
| **Azure Center for SAP solutions administrator** |
375+
376+
| Minimum permissions for *users* |
377+
| ------------------------------- |
378+
| `Microsoft.Workloads/sapVirtualInstances/applicationInstances/stop/action` |
379+
380+
| Built-in roles for *user-assigned managed identities* |
381+
| ---------------------------------------------------- |
382+
| **Azure Center for SAP solutions service role** |
383+
384+
| Minimum permissions for *user-assigned managed identities* |
385+
| ---------------------------------------------------------- |
386+
| `Microsoft.Compute/virtualMachines/read` |
387+
| `Microsoft.Compute/virtualMachines/extensions/read` |
388+
| `Microsoft.Compute/virtualMachines/extensions/write` |
389+
| `Microsoft.Compute/virtualMachines/instanceView/read` |
390+
391+
## Start SAP HANA Database instance
392+
To start the SAP HANA Database instance from a VIS resource, a *user* and *user-assigned managed identity* requires the following role or permissions.
393+
394+
| Built-in roles for *users* |
395+
| ------------------------- |
396+
| **Azure Center for SAP solutions administrator** |
397+
398+
| Minimum permissions for *users* |
399+
| ------------------------------- |
400+
| `Microsoft.Workloads/sapVirtualInstances/databaseInstances/start/action` |
401+
402+
| Built-in roles for *user-assigned managed identities* |
403+
| ---------------------------------------------------- |
404+
| **Azure Center for SAP solutions service role** |
405+
406+
| Minimum permissions for *user-assigned managed identities* |
407+
| ---------------------------------------------------------- |
408+
| `Microsoft.Compute/virtualMachines/read` |
409+
| `Microsoft.Compute/virtualMachines/extensions/read` |
410+
| `Microsoft.Compute/virtualMachines/extensions/write` |
411+
| `Microsoft.Compute/virtualMachines/instanceView/read` |
412+
413+
## Stop SAP HANA Database instance
414+
To stop the SAP HANA Database instance from a VIS resource, a *user* and *user-assigned managed identity* requires the following role or permissions.
415+
416+
| Built-in roles for *users* |
417+
| ------------------------- |
418+
| **Azure Center for SAP solutions administrator** |
419+
420+
| Minimum permissions for *users* |
421+
| ------------------------------- |
422+
| `Microsoft.Workloads/sapVirtualInstances/databaseInstances/stop/action` |
423+
424+
| Built-in roles for *user-assigned managed identities* |
425+
| ---------------------------------------------------- |
426+
| **Azure Center for SAP solutions service role** |
427+
428+
| Minimum permissions for *user-assigned managed identities* |
429+
| ---------------------------------------------------------- |
430+
| `Microsoft.Compute/virtualMachines/read` |
431+
| `Microsoft.Compute/virtualMachines/extensions/read` |
432+
| `Microsoft.Compute/virtualMachines/extensions/write` |
433+
| `Microsoft.Compute/virtualMachines/instanceView/read` |
434+
303435
## View cost analysis
304436

305437
To view the cost analysis, a *user* requires the following role or permissions.

0 commit comments

Comments
 (0)