@@ -30,14 +30,44 @@ To add any missing permissions listed here, see [Update a custom role](../role-b
30
30
31
31
## Permissions
32
32
33
- Depending on whether you're creating new resources or using existing ones, add the appropriate permissions from the following list:
34
-
35
- | Resource | Resource status | Required Azure permissions |
36
- | ---| ---| ---|
37
- | Subnet | Create new| Microsoft.Network/virtualNetworks/subnets/write<br >Microsoft.Network/virtualNetworks/subnets/join/action |
38
- | Subnet | Use existing| Microsoft.Network/virtualNetworks/subnets/read<br >Microsoft.Network/virtualNetworks/subnets/join/action |
39
- | IP addresses| Create new| Microsoft.Network/publicIPAddresses/write<br >Microsoft.Network/publicIPAddresses/join/action |
40
- | IP addresses | Use existing| Microsoft.Network/publicIPAddresses/read<br >Microsoft.Network/publicIPAddresses/join/action |
33
+ When creating or updating the resources below, add the appropriate permissions from the following list:
34
+
35
+ ### Virtual hub resources
36
+
37
+ | Resource | Required Azure permissions |
38
+ | ---| ---|
39
+ | virtualHubs | Microsoft.Network/virtualNetworks/peer/action <br >Microsoft.Network/virtualWans/join/action |
40
+ | virtualHubs/hubVirtualNetworkConnections | Microsoft.Network/virtualNetworks/peer/action <br >Microsoft.Network/virtualHubs/routeMaps/read <br >Microsoft.Network/virtualHubs/hubRouteTables/read |
41
+ | virtualHubs/bgpConnections | Microsoft.Network/virtualHubs/hubVirtualNetworkConnections/read |
42
+ | virtualHubs/hubRouteTables | Microsoft.Network/securityPartnerProviders/read <br >Microsoft.Network/virtualHubs/hubVirtualNetworkConnections/read <br >Microsoft.Network/networkVirtualAppliances/read <br >Microsoft.Network/azurefirewalls/read |
43
+ | virtualHubs/routingIntent | Microsoft.Network/securityPartnerProviders/read <br >Microsoft.Network/networkVirtualAppliances/read <br >Microsoft.Network/azurefirewalls/read |
44
+
45
+ ### ExpressRoute gateway resources
46
+
47
+ | Resource | Required Azure permissions |
48
+ | ---| ---|
49
+ | expressroutegateways | Microsoft.Network/virtualHubs/read <br >Microsoft.Network/virtualHubs/hubRouteTables/read <br >Microsoft.Network/virtualHubs/routeMaps/read <br >Microsoft.Network/expressRouteGateways/expressRouteConnections/read |
50
+ | expressRouteGateways/expressRouteConnections | Microsoft.Network/virtualHubs/hubRouteTables/read <br >Microsoft.Network/virtualHubs/routeMaps/read |
51
+
52
+
53
+ ### VPN resources
54
+
55
+ | Resource | Required Azure permissions |
56
+ | ---| ---|
57
+ | p2svpngateways | Microsoft.Network/virtualHubs/read <br >Microsoft.Network/virtualHubs/hubRouteTables/read <br >Microsoft.Network/virtualHubs/routeMaps/read <br >Microsoft.Network/vpnServerConfigurations/read |
58
+ | p2sVpnGateways/p2sConnectionConfigurations | Microsoft.Network/virtualHubs/hubRouteTables/read <br >Microsoft.Network/virtualHubs/routeMaps/read |
59
+ | vpngateways | Microsoft.Network/virtualHubs/read <br >Microsoft.Network/virtualHubs/hubRouteTables/read <br >Microsoft.Network/virtualHubs/routeMaps/read <br >Microsoft.Network/vpnGateways/vpnConnections/read |
60
+ | vpnsites | Microsoft.Network/virtualWans/read |
61
+
62
+ ### NVA resources
63
+
64
+ NVAs (Network Virtual Appliances) in Virtual WAN are typically deployed through Azure managed applications or directly via NVA orchestration software. For more information on how to properly assign permissions to managed applications or NVA orchestration software, see instructions [ here] ( aka.ms/ ) .
65
+
66
+ | Resource | Required Azure permissions |
67
+ | ---| ---|
68
+ | networkVirtualAppliances | Microsoft.Network/virtualHubs/read |
69
+ | networkVirtualAppliances/networkVirtualApplianceConnections | Microsoft.Network/virtualHubs/routeMaps/read <br >Microsoft.Network/virtualHubs/hubRouteTables/read |
70
+
41
71
42
72
For more information, see [ Azure permissions for Networking] ( ../role-based-access-control/permissions/networking.md ) and [ Virtual network permissions] ( ../virtual-network/virtual-network-manage-subnet.md#permissions ) .
43
73
0 commit comments