Skip to content

Commit dcbe33a

Browse files
authored
Merge pull request #294914 from maud-lv/ml-amgcreatoradmin
Add information about Creator can admin option
2 parents 35ba6fb + 1f658c7 commit dcbe33a

File tree

2 files changed

+31
-19
lines changed

2 files changed

+31
-19
lines changed

articles/managed-grafana/quickstart-managed-grafana-cli.md

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ms.service: azure-managed-grafana
55
ms.topic: quickstart
66
author: maud-lv
77
ms.author: malev
8-
ms.date: 12/17/2024
8+
ms.date: 03/14/2025
99
ms.devlang: azurecli
1010
ms.custom: engagement-fy23, devx-track-azurecli
1111
# customer intent: As a developer or a data analyst, I want to create a new Azure Managed Grafana workspace using the Azure CLI.
@@ -16,17 +16,20 @@ ms.custom: engagement-fy23, devx-track-azurecli
1616
Get started using Azure Managed Grafana by creating an Azure Managed Grafana workspace using the Azure CLI.
1717

1818
>[!NOTE]
19-
> Azure Managed Grafana has [two pricing plans](overview.md#service-tiers). This guides takes you through creating a new workspace in the Standard plan. To generate a workspace in the Essential (preview) plan, [use the Azure portal](quickstart-managed-grafana-portal.md).
19+
> Azure Managed Grafana has [two pricing plans](overview.md#service-tiers). This guide takes you through creating a new workspace in the Standard plan. To create a workspace in the Essential (preview) plan, [use the Azure portal](quickstart-managed-grafana-portal.md).
2020

2121
## Prerequisites
2222

2323
- An Azure account for work or school with an active subscription. [Create an account for free](https://azure.microsoft.com/free).
2424
- Minimum required role to create a workspace: resource group Contributor.
2525
- Minimum required role to access the Grafana UI: resource group Owner.
26-
>[!NOTE]
27-
> If you don't meet this requirement, once you've created a new Azure Managed Grafana workspace, ask a User Access Administrator, subscription Owner or resource group Owner to grant you a Grafana Admin, Grafana Editor or Grafana Viewer role on the workspace.
2826

29-
[!INCLUDE [azure-cli-prepare-your-environment-no-header.md](~/reusable-content/azure-cli/azure-cli-prepare-your-environment-no-header.md)]
27+
> [!NOTE]
28+
> If you're not a resource group Owner:
29+
> - once you've created the Azure Managed Grafana workspace, ask a User Access Administrator, subscription Owner or resource group Owner to grant you a Grafana Admin, Grafana Editor or Grafana Viewer role
30+
> - or consider creating the workspace using the **Creator can admin (Preview)** feature available from the Azure portal. Refer to the [Azure portal quickstart](quickstart-managed-grafana-portal.md) for more information.
31+
32+
[!INCLUDE [azure-cli-prepare-your-environment-no-header.md](~/reusable-content/azure-cli/azure-cli-prepare-your-environment-no-header.md)]
3033

3134
## Sign in to Azure
3235

articles/managed-grafana/quickstart-managed-grafana-portal.md

Lines changed: 23 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -18,9 +18,6 @@ In this quickstart, you get started with Azure Managed Grafana by creating an Az
1818

1919
- An Azure account for work or school and an active subscription. [Create an account for free](https://azure.microsoft.com/free).
2020
- Minimum required role to create a workspace: resource group Contributor.
21-
- Minimum required role to access the Grafana UI: resource group Owner.
22-
>[!NOTE]
23-
> If you don't meet this requirement, once you've created a new Azure Managed Grafana workspace, ask a User Access Administrator, subscription Owner or resource group Owner to grant you a Grafana Admin, Grafana Editor or Grafana Viewer role on the workspace.
2421

2522
## Create an Azure Managed Grafana workspace
2623

@@ -48,17 +45,26 @@ In this quickstart, you get started with Azure Managed Grafana by creating an Az
4845
- **Enable API key creation** is set to **Disable** by default.
4946
- If you've opted for the Standard plan, optionally enable the **Deterministic outbound IP** feature, which is set to **Disable** by default.
5047

51-
1. Select **Next : Permission >** to control access rights for your Grafana workspace and data sources:
52-
1. **System assigned managed identity** is set to **On**.
48+
1. Select **Next : Permission >** to control access rights for your Grafana instance and data sources:
49+
- **System assigned managed identity** is set to **On**.
5350

54-
>[!NOTE]
55-
>You can use a user-assigned managed identity instead of the default system-assigned managed identity once the Azure Managed Grafana resource is deployed. To learn more, go to [Set up Azure Managed Grafana authentication and permissions (preview)](how-to-authentication-permissions.md).
51+
> [!NOTE]
52+
> You can use a user-assigned managed identity instead of the default system-assigned managed identity once the Azure Managed Grafana resource is deployed. For more information, go to [Set up Azure Managed Grafana authentication and permissions (preview)](how-to-authentication-permissions.md).
5653

57-
1. The box **Add role assignment to this identity with 'Monitoring Reader' role on target subscription** is checked by default.
54+
- If you're a subscription Owner or a User Access Administrator:
55+
- the box **Add role assignment to this identity with 'Monitoring Reader' role on target subscription** is checked by default. This role assignment allows Azure Managed Grafana to access and display monitoring data from various Azure services.
56+
- the box **Include myself** under **Grafana administrator role** is checked. This option grants you the Grafana administrator role, and lets you manage access rights. Optionally select **Add** to share this right with team members.
57+
- If you're not a subscription Owner or a User Access Administrator, you can either:
58+
- ask a subscription Owner or a User Access Administrator to assign you the Grafana Admin role
59+
- or enable **Creator can admin (Preview)**. This option available in preview grants you the required permissions to access and manage the Grafana resource.
5860

59-
1. The box **Include myself** under **Grafana administrator role** is checked. This option grants you the Grafana administrator role, and lets you manage access rights. You can give this right to more members by selecting **Add**. If this option grays out for you, ask someone with the Owner role on the subscription to assign you the Grafana Admin role.
60-
61-
1. If you've opted for the Standard plan, optionally disable public access and create a private endpoint that can access your resource.
61+
> [!NOTE]
62+
> The **Creator can admin (Preview)** option can only be enabled when creating the workspace. Later on, it can be disabled from the **Configuration** menu if the workspace creator doesn't need this level of access anymore. Once disabled, it cannot be enabled again. If this option is disabled and the user needs to access this Grafana instance again, they will need [a Grafana role](how-to-manage-access-permissions-users-identities.md).
63+
64+
> [!NOTE]
65+
> The **Creator can admin (Preview)** option may not be available in some specific scenarios. For example, it doesn't support workspaces managed by Cloud Solution Providers (CSPs). In CSP scenarios, the necessary information about the individual creator of the resource is not accessible. As a result, the feature cannot grant administrative privileges to the creator.
66+
67+
1. If you've opted for the Standard plan, in the **Networking** tab, optionally disable public access and create a private endpoint that can access your resource.
6268

6369
1. Optionally select **Next : Tags** and add tags to categorize resources.
6470

@@ -68,13 +74,16 @@ In this quickstart, you get started with Azure Managed Grafana by creating an Az
6874

6975
1. Once the deployment is complete, select **Go to resource** to open your resource.
7076

71-
1. In the **Overview** tab's Essentials section, select the **Endpoint** URL. Single sign-on via Microsoft Entra ID has been configured for you automatically. If prompted, enter your Azure account.
77+
1. In the **Overview** tab, select the **Endpoint** URL. Single sign-on via Microsoft Entra ID has been configured for you automatically. If prompted, enter your Azure account.
7278

7379
:::image type="content" source="media/quickstart-portal/grafana-overview.png" alt-text="Screenshot of the Azure portal. Endpoint URL display.":::
7480

81+
You can now start interacting with the Grafana application to configure data sources, create dashboards, reports and alerts. Suggested read: [Monitor Azure services and applications using Grafana](/azure/azure-monitor/visualize/grafana-plugin).
82+
7583
:::image type="content" source="media/quickstart-portal/grafana-ui.png" alt-text="Screenshot of an Azure Managed Grafana workspace.":::
7684

77-
You can now start interacting with the Grafana application to configure data sources, create dashboards, reports and alerts. Suggested read: [Monitor Azure services and applications using Grafana](/azure/azure-monitor/visualize/grafana-plugin).
85+
> [!IMPORTANT]
86+
> The **Creator can admin (Preview)** option is designed to be used for testing purposes. Whenever possible, we recommend assigning a [Grafana role](how-to-manage-access-permissions-users-identities.md) to all team members who need to access the Grafana portal and disabling the **Creator can edit** option.
7887

7988
## Clean up resources
8089

@@ -84,7 +93,7 @@ In the preceding steps, you created an Azure Managed Grafana workspace in a new
8493
1. In the **Overview** page, make sure that the listed resources are the ones you want to delete.
8594
1. Select **Delete**, type the name of your resource group in the text box, and then select **Delete**.
8695

87-
## Next steps
96+
## Next step
8897

8998
> [!div class="nextstepaction"]
9099
> [How to configure data sources for Azure Managed Grafana](./how-to-data-source-plugins-managed-identity.md)

0 commit comments

Comments
 (0)