Skip to content

Commit efbaafc

Browse files
committed
first draft
1 parent 9cab075 commit efbaafc

File tree

2 files changed

+43
-16
lines changed

2 files changed

+43
-16
lines changed

articles/route-server/roles-permissions.md

Lines changed: 5 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -30,14 +30,11 @@ To add any missing permissions listed here, see [Update a custom role](../role-b
3030

3131
## Permissions
3232

33-
Depending on whether you're creating new resources or using existing ones, add the appropriate permissions from the following list:
34-
35-
|Resource | Resource status | Required Azure permissions |
36-
|---|---|---|
37-
| Subnet | Create new| Microsoft.Network/virtualNetworks/subnets/write<br>Microsoft.Network/virtualNetworks/subnets/join/action |
38-
| Subnet | Use existing| Microsoft.Network/virtualNetworks/subnets/read<br>Microsoft.Network/virtualNetworks/subnets/join/action |
39-
| IP addresses| Create new| Microsoft.Network/publicIPAddresses/write<br>Microsoft.Network/publicIPAddresses/join/action |
40-
| IP addresses | Use existing| Microsoft.Network/publicIPAddresses/read<br>Microsoft.Network/publicIPAddresses/join/action |
33+
When creating or updating the resources below, add the appropriate permissions from the following list:
34+
35+
|Resource | Required Azure permissions |
36+
|---|---|
37+
| virtualHubs/ipConfigurations | Microsoft.Network/publicIPAddresses/join/action <br>Microsoft.Network/virtualNetworks/subnets/join/action |
4138

4239
For more information, see [Azure permissions for Networking](../role-based-access-control/permissions/networking.md) and [Virtual network permissions](../virtual-network/virtual-network-manage-subnet.md#permissions).
4340

articles/virtual-wan/roles-permissions.md

Lines changed: 38 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -30,14 +30,44 @@ To add any missing permissions listed here, see [Update a custom role](../role-b
3030

3131
## Permissions
3232

33-
Depending on whether you're creating new resources or using existing ones, add the appropriate permissions from the following list:
34-
35-
|Resource | Resource status | Required Azure permissions |
36-
|---|---|---|
37-
| Subnet | Create new| Microsoft.Network/virtualNetworks/subnets/write<br>Microsoft.Network/virtualNetworks/subnets/join/action |
38-
| Subnet | Use existing| Microsoft.Network/virtualNetworks/subnets/read<br>Microsoft.Network/virtualNetworks/subnets/join/action |
39-
| IP addresses| Create new| Microsoft.Network/publicIPAddresses/write<br>Microsoft.Network/publicIPAddresses/join/action |
40-
| IP addresses | Use existing| Microsoft.Network/publicIPAddresses/read<br>Microsoft.Network/publicIPAddresses/join/action |
33+
When creating or updating the resources below, add the appropriate permissions from the following list:
34+
35+
### Virtual hub resources
36+
37+
|Resource | Required Azure permissions |
38+
|---|---|
39+
| virtualHubs | Microsoft.Network/virtualNetworks/peer/action <br>Microsoft.Network/virtualWans/join/action |
40+
| virtualHubs/hubVirtualNetworkConnections | Microsoft.Network/virtualNetworks/peer/action <br>Microsoft.Network/virtualHubs/routeMaps/read <br>Microsoft.Network/virtualHubs/hubRouteTables/read |
41+
| virtualHubs/bgpConnections | Microsoft.Network/virtualHubs/hubVirtualNetworkConnections/read |
42+
| virtualHubs/hubRouteTables | Microsoft.Network/securityPartnerProviders/read <br>Microsoft.Network/virtualHubs/hubVirtualNetworkConnections/read <br>Microsoft.Network/networkVirtualAppliances/read <br>Microsoft.Network/azurefirewalls/read |
43+
| virtualHubs/routingIntent | Microsoft.Network/securityPartnerProviders/read <br>Microsoft.Network/networkVirtualAppliances/read <br>Microsoft.Network/azurefirewalls/read |
44+
45+
### ExpressRoute gateway resources
46+
47+
|Resource | Required Azure permissions |
48+
|---|---|
49+
| expressroutegateways | Microsoft.Network/virtualHubs/read <br>Microsoft.Network/virtualHubs/hubRouteTables/read <br>Microsoft.Network/virtualHubs/routeMaps/read <br>Microsoft.Network/expressRouteGateways/expressRouteConnections/read |
50+
| expressRouteGateways/expressRouteConnections | Microsoft.Network/virtualHubs/hubRouteTables/read <br>Microsoft.Network/virtualHubs/routeMaps/read |
51+
52+
53+
### VPN resources
54+
55+
|Resource | Required Azure permissions |
56+
|---|---|
57+
| p2svpngateways | Microsoft.Network/virtualHubs/read <br>Microsoft.Network/virtualHubs/hubRouteTables/read <br>Microsoft.Network/virtualHubs/routeMaps/read <br>Microsoft.Network/vpnServerConfigurations/read |
58+
| p2sVpnGateways/p2sConnectionConfigurations | Microsoft.Network/virtualHubs/hubRouteTables/read <br>Microsoft.Network/virtualHubs/routeMaps/read |
59+
| vpngateways | Microsoft.Network/virtualHubs/read <br>Microsoft.Network/virtualHubs/hubRouteTables/read <br>Microsoft.Network/virtualHubs/routeMaps/read <br>Microsoft.Network/vpnGateways/vpnConnections/read |
60+
| vpnsites | Microsoft.Network/virtualWans/read |
61+
62+
### NVA resources
63+
64+
NVAs (Network Virtual Appliances) in Virtual WAN are typically deployed through Azure managed applications or directly via NVA orchestration software. For more information on how to properly assign permissions to managed applications or NVA orchestration software, see instructions [here](aka.ms/).
65+
66+
|Resource | Required Azure permissions |
67+
|---|---|
68+
| networkVirtualAppliances | Microsoft.Network/virtualHubs/read |
69+
| networkVirtualAppliances/networkVirtualApplianceConnections | Microsoft.Network/virtualHubs/routeMaps/read <br>Microsoft.Network/virtualHubs/hubRouteTables/read |
70+
4171

4272
For more information, see [Azure permissions for Networking](../role-based-access-control/permissions/networking.md) and [Virtual network permissions](../virtual-network/virtual-network-manage-subnet.md#permissions).
4373

0 commit comments

Comments
 (0)