Skip to content

Commit 6243ba6

Browse files
Update rbac-permissions.md
Include roles and permissions on exactly "who" can Approve an incoming private endpoint connection. This is critical as enterprise users has strict role-based-access control on who can do the Approval. Proposed content is from this link: https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/api-management/private-endpoint.md
1 parent 6146de5 commit 6243ba6

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

articles/private-link/rbac-permissions.md

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -129,6 +129,16 @@ This section lists the granular permissions required to deploy a private link se
129129
}
130130
```
131131

132+
## Approval RBAC for private endpoint
133+
134+
Typically, a network administrator creates a private endpoint. Depending on your Azure role-based access control (RBAC) permissions, a private endpoint that you create is either *automatically approved* to send traffic to the API Management instance, or requires the resource owner to *manually approve* the connection.
135+
136+
137+
|Approval method |Minimum RBAC permissions |
138+
|---------|---------|
139+
|Automatic | `Microsoft.Network/virtualNetworks/**`<br/>`Microsoft.Network/virtualNetworks/subnets/**`<br/>`Microsoft.Network/privateEndpoints/**`<br/>`Microsoft.Network/networkinterfaces/**`<br/>`Microsoft.Network/locations/availablePrivateEndpointTypes/read`<br/>`Microsoft.ApiManagement/service/**`<br/>`Microsoft.ApiManagement/service/privateEndpointConnections/**` |
140+
|Manual | `Microsoft.Network/virtualNetworks/**`<br/>`Microsoft.Network/virtualNetworks/subnets/**`<br/>`Microsoft.Network/privateEndpoints/**`<br/>`Microsoft.Network/networkinterfaces/**`<br/>`Microsoft.Network/locations/availablePrivateEndpointTypes/read` |
141+
132142
## Next steps
133143

134144
For more information on private endpoint and private link services in Azure Private link, see:

0 commit comments

Comments
 (0)