Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

💡 Feature Request - Add options for Privileged Role Assignment as part of Landing Zone deployment #35

Open
tulpy opened this issue Feb 3, 2023 · 4 comments
Labels
Area: RBAC enhancement New feature or request long-term We will do it, but will take a longer amount of time due to complexity/priorities

Comments

@tulpy
Copy link

tulpy commented Feb 3, 2023

Describe the solution you'd like

Thanks for the community update session earlier this week, it was good to see the direction of ALZ and future focus on expanding the offering. I have been using the Vending approach recently and had some feedback from customers to compliment the role assignment with privileged role assignments as part of the deployment.

Describe alternatives you've considered

Follow a similar concept to the role assignment but include Azure AD PIM role assignments.

  • optional
  • boolean true / false
  • pass in an array of objects for role assignments
  • applied to the subscription or Resource Group context

Additional context

This approach can address permanent assigned access for "read" type access using role assignments and eligible access for "write" access using Azure AD PIM.

@tulpy tulpy added the enhancement New feature or request label Feb 3, 2023
@ghost ghost added the Needs: Triage 🔍 Needs triaging by the team label Feb 3, 2023
@jtracey93
Copy link
Collaborator

jtracey93 commented Feb 6, 2023

Hey @tulpy,

Good feature ask. We will add to our backlog and track in AB#26622.

cc: @matt-FFFFFF

@jtracey93 jtracey93 added Area: RBAC long-term We will do it, but will take a longer amount of time due to complexity/priorities and removed Needs: Triage 🔍 Needs triaging by the team labels Mar 20, 2023
@MilesCameron-DMs
Copy link
Contributor

Hey @jtracey93 or @matt-FFFFFF is there any publicly accessible visibility of this feature request?

If not and its not on the horizon, i will tackle it now.

My first thought was to use what has been set out in the alz-bicep repo for RBAC access but i haven't looked yet.

@jtracey93
Copy link
Collaborator

Hey @MilesCameron-DMs,

It's up there, we are just getting the RP registration feature out first on the bicep front and then we have the following to prioritise and work on:

What would you order them in?

@MilesCameron-DMs
Copy link
Contributor

@jtracey93 i think i would probably put them in the order you have them 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Area: RBAC enhancement New feature or request long-term We will do it, but will take a longer amount of time due to complexity/priorities
Projects
None yet
Development

No branches or pull requests

3 participants