|
| 1 | +--- |
| 2 | + title: include file |
| 3 | + description: include file |
| 4 | + services: event-grid |
| 5 | + author: spelluru |
| 6 | + ms.service: event-grid |
| 7 | + ms.topic: include |
| 8 | + ms.date: 10/31/2022 |
| 9 | + ms.author: spelluru |
| 10 | + ms.custom: include file |
| 11 | +--- |
| 12 | + |
| 13 | +## Authorize partner to create a partner topic |
| 14 | + |
| 15 | +You must grant your consent to the partner to create partner topics in a resource group that you designate. This authorization has an expiration time. It's effective for the time period you specify between 1 to 365 days. |
| 16 | + |
| 17 | +> [!IMPORTANT] |
| 18 | +> For a greater security stance, specify the minimum expiration time that offers the partner enough time to configure your events to flow to Event Grid and to provision your partner topic. Your partner won't be able to create resources (partner topics) in your Azure subscription after the authorization expiration time. |
| 19 | +
|
| 20 | +> [!NOTE] |
| 21 | +> Event Grid started enforcing authorization checks to create partner topics around June 30th, 2022. |
| 22 | +
|
| 23 | +Following example shows the way to create a partner configuration resource that contains the partner authorization. You must identify the partner by providing either its **partner registration ID** or the **partner name**. Both can be obtained from your partner, but only one of them is required. For your convenience, the following examples leave a sample expiration time in the UTC format. |
| 24 | + |
| 25 | +### Azure portal |
| 26 | + |
| 27 | +1. Sign in to the [Azure portal](https://portal.azure.com). |
| 28 | +1. In the search bar at the top, enter **Partner Configurations**, and select **Event Grid Partner Configurations** under **Services** in the results. |
| 29 | +1. On the **Event Grid Partner Configurations** page, select **Create Event Grid partner configuration** button on the page (or) select **+ Create** on the command bar. |
| 30 | + |
| 31 | + :::image type="content" source="./media/subscribe-to-partner-events/partner-configurations.png" alt-text="Screenshot showing the Event Grid Partner Configurations with the list of partner configurations and a link to create a partner registration."::: |
| 32 | +1. On the **Create Partner Configuration** page, do the following steps: |
| 33 | + 1. In the **Project Details** section, select the **Azure subscription** and the **resource group** where you want to allow the partner to create a partner topic. |
| 34 | + 1. In the **Partner Authorizations** section, specify a default expiration time for partner authorizations defined in this configuration. |
| 35 | + 1. To provide your authorization for a partner to create partner topics in the specified resource group, select **+ Partner Authorization** link. |
| 36 | + |
| 37 | + :::image type="content" source="./media/subscribe-to-partner-events/partner-authorization-configuration.png" alt-text="Screenshot showing the Create Partner Configuration page with the Partner Authorization link selected."::: |
| 38 | + |
| 39 | +1. On the **Add partner authorization to create resources** page, you see a list of **verified partners**. A verified partner is a partner whose identity has been validated by Microsoft. You can select a verified partner, and select **Add** button at the bottom to give the partner the authorization to add a partner topic in your resource group. This authorization is effective up to the expiration time. |
| 40 | + |
| 41 | + You also have an option to authorize a **non-verified partner. ** Unless the partner is an entity that you know well, for example, an organization within your company, it's strongly encouraged that you only work with verified partners. If the partner isn't yet verified, encourage them to get verified by asking them to contact the Event Grid team at [email protected]. |
| 42 | + |
| 43 | + 1. To authorize a **verified partner**: |
| 44 | + 1. Select the partner from the list. |
| 45 | + 1. Specify **authorization expiration time**. |
| 46 | + 1. select **Add**. |
| 47 | + |
| 48 | + :::image type="content" source="./media/subscribe-to-partner-events/add-verified-partner.png" alt-text="Screenshot for granting a verified partner the authorization to create resources in your resource group."::: |
| 49 | + 1. To authorize a non-verified partner, select **Authorize non-verified partner**, and follow these steps: |
| 50 | + 1. Enter the **partner registration ID**. You need to ask your partner for this ID. |
| 51 | + 1. Specify authorization expiration time. |
| 52 | + 1. Select **Add**. |
| 53 | + |
| 54 | + :::image type="content" source="./media/subscribe-to-partner-events/add-non-verified-partner.png" alt-text="Screenshot for granting a non-verified partner the authorization to create resources in your resource group."::: |
| 55 | + |
| 56 | + > [!IMPORTANT] |
| 57 | + > Your partner won't be able to create resources (partner topics) in your Azure subscription after the authorization expiration time. |
| 58 | +1. Back on the **Create Partner Configuration** page, verify that the partner is added to the partner authorization list at the bottom. |
| 59 | +1. Select **Review + create** at the bottom of the page. |
| 60 | + |
| 61 | + :::image type="content" source="./media/subscribe-to-partner-events/create-partner-registration.png" alt-text="Screenshot showing the Create Partner Configuration page with the partner authorization you just added."::: |
| 62 | +1. On the **Review** page, review all settings, and then select **Create** to create the partner registration. |
| 63 | + |
| 64 | + |
0 commit comments