Skip to content

Commit 6e02beb

Browse files
Merge pull request #273409 from chen-karen/patch-4
Update built-in-roles.md
2 parents 116ccfd + 22a307b commit 6e02beb

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

articles/key-vault/managed-hsm/built-in-roles.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,9 @@ Azure Key Vault Managed HSM local role-based access control (RBAC) has several b
1717

1818
To allow a principal to perform an operation, you must assign them a role that grants them permissions to perform that operations. All these roles and operations allow you to manage permissions only for *data plane* operations. For *management plane* operations, see [Azure built-in roles](../../role-based-access-control/built-in-roles.md) and [Secure access to your managed HSMs](secure-your-managed-hsm.md).
1919

20+
> [!NOTE]
21+
> Service principal group access is not supported for performing data plane operations. Only user group access is supported for data plane operations. Service principals must be added to the role directly.
22+
2023
To manage control plane permissions for the Managed HSM resource, you must use [Azure role-based access control (Azure RBAC)](../../role-based-access-control/overview.md). Some examples of control plane operations are to create a new managed HSM, or to update, move, or delete a managed HSM.
2124

2225
## Built-in roles

0 commit comments

Comments
 (0)