Skip to content

Commit 9b61b3c

Browse files
Merge pull request #277290 from mgreenegit/patch-8
Add permissions required to deploy extensions
2 parents 0e07c97 + 20580ca commit 9b61b3c

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

articles/azure-arc/servers/manage-vm-extensions.md

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -96,6 +96,16 @@ If they aren't already registered, follow the steps under [Register Azure resour
9696

9797
Be sure to review the documentation for each VM extension referenced in the previous table to understand if it has any network or system requirements. This can help you avoid experiencing any connectivity issues with an Azure service or feature that relies on that VM extension.
9898

99+
### Required Permissions
100+
101+
To deploy an extension to Arc-enabled servers, a user requires the following permissions.
102+
103+
- `microsoft.hybridcompute/machines/read`
104+
- `microsoft.hybridcompute/machines/extensions/read`
105+
- `microsoft.hybridcompute/machines/extensions/write`
106+
107+
The role **Azure Connected Machine Resource Administrator** includes the permissions required to deploy extensions, however it also includes permission to delete Arc-enabled server resources.
108+
99109
### Log Analytics VM extension
100110

101111
The Log Analytics agent VM extension for Linux requires Python 2.x is installed on the target machine.

0 commit comments

Comments
 (0)