Skip to content

Commit 548f53d

Browse files
authored
Merge pull request #106718 from weixian-zhang/patch-1
docs(rbac-permissions.md): Include RBAC and permissions for Private Endpoint Approval
2 parents 6b1dfc3 + 6243ba6 commit 548f53d

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

articles/private-link/rbac-permissions.md

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -129,6 +129,16 @@ This section lists the granular permissions required to deploy a private link se
129129
}
130130
```
131131

132+
## Approval RBAC for private endpoint
133+
134+
Typically, a network administrator creates a private endpoint. Depending on your Azure role-based access control (RBAC) permissions, a private endpoint that you create is either *automatically approved* to send traffic to the API Management instance, or requires the resource owner to *manually approve* the connection.
135+
136+
137+
|Approval method |Minimum RBAC permissions |
138+
|---------|---------|
139+
|Automatic | `Microsoft.Network/virtualNetworks/**`<br/>`Microsoft.Network/virtualNetworks/subnets/**`<br/>`Microsoft.Network/privateEndpoints/**`<br/>`Microsoft.Network/networkinterfaces/**`<br/>`Microsoft.Network/locations/availablePrivateEndpointTypes/read`<br/>`Microsoft.ApiManagement/service/**`<br/>`Microsoft.ApiManagement/service/privateEndpointConnections/**` |
140+
|Manual | `Microsoft.Network/virtualNetworks/**`<br/>`Microsoft.Network/virtualNetworks/subnets/**`<br/>`Microsoft.Network/privateEndpoints/**`<br/>`Microsoft.Network/networkinterfaces/**`<br/>`Microsoft.Network/locations/availablePrivateEndpointTypes/read` |
141+
132142
## Next steps
133143

134144
For more information on private endpoint and private link services in Azure Private link, see:

0 commit comments

Comments
 (0)