Skip to content

Commit aa4bcc4

Browse files
committed
Updated constrained delegation UI and steps
1 parent d27486a commit aa4bcc4

File tree

5 files changed

+11
-21
lines changed

5 files changed

+11
-21
lines changed

articles/role-based-access-control/delegate-role-assignments-portal.md

Lines changed: 9 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -59,16 +59,11 @@ There are two ways that you can add a condition. You can use a condition templat
5959

6060
# [Template](#tab/template)
6161

62-
1. On the **Conditions** tab under **Delegation type**, select the **Constrained (recommended)** option.
62+
1. On the **Conditions** tab under **What user can do**, select the **Allow user to only assign selected roles to selected principals (fewer privileges)** option.
6363

64-
| Option | Select this option to |
65-
| --- | --- |
66-
| **Constrained (recommended)** | Pick the roles or principals the user can use in role assignments |
67-
| **Not constrained** | Allow the user to assign any role to any principal |
68-
69-
:::image type="content" source="./media/shared/condition-constrained.png" alt-text="Screenshot of Add role assignment with the Constrained option selected." lightbox="./media/shared/condition-constrained.png":::
64+
:::image type="content" source="./media/shared/condition-constrained.png" alt-text="Screenshot of Add role assignment with the constrained option selected." lightbox="./media/shared/condition-constrained.png":::
7065

71-
1. Select **Add condition**.
66+
1. Select **Select roles and principals**.
7267

7368
The Add role assignment condition page appears with a list of condition templates.
7469

@@ -78,13 +73,13 @@ There are two ways that you can add a condition. You can use a condition templat
7873

7974
| Condition template | Select this template to |
8075
| --- | --- |
81-
| Constrain roles | Constrain the roles a user can assign |
82-
| Constrain roles and principal types | Constrain the roles a user can assign and the types of principals the user can assign roles to |
83-
| Constrain roles and principals | Constrain the roles a user can assign and the principals the user can assign roles to |
76+
| Constrain roles | Allow user to only assign roles you select |
77+
| Constrain roles and principal types | Allow user to only assign roles you select<br/>Allow user to only assign these roles to principal types you select (users, groups, or service principals) |
78+
| Constrain roles and principals | Allow user to only assign roles you select<br/>Allow user to only assign these roles to principals you select |
8479

8580
1. In the configure pane, add the required configurations.
8681

87-
:::image type="content" source="./media/delegate-role-assignments-portal/condition-template-configure-pane.png" alt-text="Screenshot of configure pane for a condition with selection added." lightbox="./media/delegate-role-assignments-portal/condition-template-configure-pane.png":::
82+
:::image type="content" source="./media/shared/condition-template-configure-pane.png" alt-text="Screenshot of configure pane for a condition with selection added." lightbox="./media/shared/condition-template-configure-pane.png":::
8883

8984
1. Select **Save** to add the condition to the role assignment.
9085

@@ -94,16 +89,11 @@ If the condition templates don't work for your scenario or if you want more cont
9489

9590
### Open condition editor
9691

97-
1. On the **Conditions** tab under **Delegation type**, select the **Constrained (recommended)** option.
98-
99-
| Option | Select this option to |
100-
| --- | --- |
101-
| **Constrained (recommended)** | Pick the roles or principals the user can use in role assignments |
102-
| **Not constrained** | Allow the user to assign any role to any principal |
92+
1. On the **Conditions** tab under **What user can do**, select the **Allow user to only assign selected roles to selected principals (fewer privileges)** option.
10393

10494
:::image type="content" source="./media/shared/condition-constrained.png" alt-text="Screenshot of Add role assignment with the Constrained option selected." lightbox="./media/shared/condition-constrained.png":::
10595

106-
1. Select **Add condition**.
96+
1. Select **Select roles and principals**.
10797

10898
The Add role assignment condition page appears with a list of condition templates.
10999

4.86 KB
Loading
5.18 KB
Loading

articles/role-based-access-control/role-assignments-portal.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -132,11 +132,11 @@ If you selected one of the following privileged roles, follow the steps in this
132132
- [Role Based Access Control Administrator](built-in-roles.md#role-based-access-control-administrator)
133133
- [User Access Administrator](built-in-roles.md#user-access-administrator)
134134

135-
1. On the **Conditions** tab under **Delegation type**, select the **Constrained (recommended)** option.
135+
1. On the **Conditions** tab under **What user can do**, select the **Allow user to only assign selected roles to selected principals (fewer privileges)** option.
136136

137137
:::image type="content" source="./media/shared/condition-constrained.png" alt-text="Screenshot of Add role assignment with the Constrained option selected." lightbox="./media/shared/condition-constrained.png":::
138138

139-
1. Click **Add condition** to add a condition that constrains the roles and principals this user can assign roles to.
139+
1. Click **Select roles and principals** to add a condition that constrains the roles and principals this user can assign roles to.
140140

141141
1. Follow the steps in [Delegate Azure role assignment management to others with conditions](delegate-role-assignments-portal.md#step-3-add-a-condition).
142142

0 commit comments

Comments
 (0)