You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/governance/management-groups/overview.md
+1-4Lines changed: 1 addition & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -216,10 +216,7 @@ There are limitations that exist when using custom roles on management groups.
216
216
is in place to reduce the number of situations where role definitions and role assignments are
217
217
disconnected. This situation happens when a subscription or management group with a role
218
218
assignment moves to a different parent that doesn't have the role definition.
219
-
- Resource provider data plane actions can't be defined in management group custom roles. This
220
-
restriction is in place as there's a latency issue with updating the data plane resource
221
-
providers. This latency issue is being worked on and these actions will be disabled from the role
222
-
definition to reduce any risks.
219
+
- Custom roles with `DataActions` can't be assigned at the management group scope. For more information, see [Custom role limits](../../role-based-access-control/custom-roles.md#custom-role-limits).
223
220
- Azure Resource Manager doesn't validate the management group's existence in the role
224
221
definition's assignable scope. If there's a typo or an incorrect management group ID listed, the
0 commit comments