Skip to content

Commit b617acc

Browse files
authored
Freshness
1 parent ed97e13 commit b617acc

1 file changed

Lines changed: 81 additions & 109 deletions

File tree

articles/sap/center-sap-solutions/manage-with-azure-rbac.md

Lines changed: 81 additions & 109 deletions
Original file line numberDiff line numberDiff line change
@@ -1,66 +1,46 @@
11
---
2-
title: Manage Azure Center for SAP solutions resources with Azure RBAC
3-
description: Use Azure role-based access control (Azure RBAC) to manage access to your SAP workloads within Azure Center for SAP solutions.
2+
title: Azure RBAC for Azure Center for SAP solutions resources
3+
description: Learn how Azure role-based access control (Azure RBAC) manages access to SAP workloads in Azure Center for SAP solutions, including built-in roles and minimum permissions.
44
author: kalyaninamuduri
55
ms.author: kanamudu
66
ms.service: sap-on-azure
77
ms.subservice: center-sap-solutions
88
ms.topic: concept-article
9-
ms.date: 02/03/2023
9+
ms.date: 04/08/2026
1010
ms.custom: template-concept
1111
# Customer intent: As an SAP system administrator, I want to manage access to SAP workloads using role-based access control, so that I can ensure effective permission management and security for deploying and managing SAP systems in Azure.
1212
---
1313

14-
# Management of Azure Center for SAP solutions resources with Azure RBAC
15-
16-
[Azure role-based access control (Azure RBAC)](../../role-based-access-control/overview.md) enables
17-
granular access management for Azure. You can use Azure RBAC to manage Virtual Instance for SAP
18-
solutions resources within Azure Center for SAP solutions. For example, you can separate duties
19-
within your team and grant only the amount of access that users need to perform their jobs.
20-
21-
*Users* or *user-assigned managed identities* require minimum roles or permissions to use the
22-
different capabilities in Azure Center for SAP solutions.
23-
24-
There are [Azure built-in roles](../../role-based-access-control/built-in-roles.md) for Azure Center
25-
for SAP solutions, or you can
26-
[create Azure custom roles](../../role-based-access-control/custom-roles.md) for more control. Azure
27-
Center for SAP solutions provides the following built-in roles to deploy and manage SAP systems on
28-
Azure:
29-
30-
- The **Azure Center for SAP solutions administrator** role has the required permissions for a user
31-
to deploy infrastructure, install SAP, and manage SAP systems from Azure Center for SAP solutions.
32-
The role allows users to:
33-
- Deploy infrastructure for a new SAP system
34-
- Install SAP software
35-
- Register existing SAP systems as a
36-
[Virtual Instance for SAP solutions (VIS)](overview.md#what-is-a-virtual-instance-for-sap-solutions)
37-
resource.
38-
- View the health and status of SAP systems.
39-
- Perform operations such as **Start** and **Stop** on the VIS resource.
40-
- Do all possible actions with Azure Center for SAP solutions, including the deletion of the VIS
41-
resource.
42-
- The **Azure Center for SAP solutions service role** is intended for use by the user-assigned
43-
managed identity. The Azure Center for SAP solutions service uses this identity to deploy and
44-
manage SAP systems. This role has permissions to support the deployment and management
45-
capabilities in Azure Center for SAP solutions.
46-
- The **Azure Center for SAP solutions reader** role has permissions to view all VIS resources.
14+
# Azure RBAC for Azure Center for SAP solutions
15+
16+
Azure [role-based access control (RBAC)](../../role-based-access-control/overview.md) lets you separate duties within your team and grant only the permissions users need to deploy and manage SAP systems in Azure Center for SAP solutions. Users or user-assigned managed identities require specific roles or minimum permissions for each capability.
4717

48-
> [!NOTE] To use an existing user-assigned managed identity for deploying a new SAP system or
49-
> registering an existing system, the user must also have the **Managed Identity Operator** role.
50-
> This role is required to assign a user-assigned managed identity to the Virtual Instance for SAP
51-
> solutions resource.
18+
This article lists the built-in roles and minimum permissions that users and user-assigned managed identities need for each Azure Center for SAP solutions capability.
5219

53-
> [!NOTE] If you're creating a new user-assigned managed identity when you deploy a new SAP system
54-
> or register an existing system, the user must also have the **Managed Identity Contributor** and
55-
> **Managed Identity Operator** roles. These roles are required to create a user-assigned identity,
56-
> make necessary role assignments to it and assign it to the VIS resource.
20+
## Built-in roles
21+
22+
Use [Azure built-in roles](../../role-based-access-control/built-in-roles.md) for Azure Center for SAP solutions, or [create Azure custom roles](../../role-based-access-control/custom-roles.md) for more control. Azure Center for SAP solutions provides the following built-in roles to deploy and manage SAP systems on Azure:
23+
24+
- The **Azure Center for SAP solutions administrator** role has the required permissions for a user to deploy infrastructure, install SAP, and manage SAP systems from Azure Center for SAP solutions. The role allows users to:
25+
- Deploy infrastructure for a new SAP system.
26+
- Install SAP software.
27+
- Register existing SAP systems as a [Virtual Instance for SAP solutions (VIS)](overview.md#what-is-a-virtual-instance-for-sap-solutions) resource.
28+
- View the health and status of SAP systems.
29+
- Perform operations such as **Start** and **Stop** on the VIS resource.
30+
- Perform all actions available in Azure Center for SAP solutions, including the deletion of the VIS resource.
31+
- The **Azure Center for SAP solutions service role** is intended for use by the user-assigned managed identity. The Azure Center for SAP solutions service uses this identity to deploy and manage SAP systems. This role has permissions to support the deployment and management capabilities in Azure Center for SAP solutions.
32+
- The **Azure Center for SAP solutions reader** role has permissions to view all VIS resources.
33+
34+
> [!NOTE]
35+
> To use an existing user-assigned managed identity for deploying a new SAP system or registering an existing system, you must also have the **Managed Identity Operator** role. This role is required to assign a user-assigned managed identity to the Virtual Instance for SAP solutions resource.
36+
>
37+
> If you're creating a new user-assigned managed identity when you deploy a new SAP system or register an existing system, you must also have the **Managed Identity Contributor** and **Managed Identity Operator** roles. These roles are required to create a user-assigned identity, make necessary role assignments to it, and assign it to the VIS resource.
5738
5839
## Deploy infrastructure for new SAP system
5940

60-
To deploy infrastructure for a new SAP system, a *user* and *user-assigned managed identity*
61-
requires the following role or permissions.
41+
To deploy infrastructure for a new SAP system, a *user* and *user-assigned managed identity* require the following role or permissions.
6242

63-
| Built-in roles for *users* |
43+
| Built-in roles for *users* |
6444
| ------------------------- |
6545
| **Azure Center for SAP solutions administrator** |
6646
| **Managed Identity Operator** |
@@ -81,15 +61,14 @@ requires the following role or permissions.
8161
| `Microsoft.Network/virtualNetworks/subnets/write` |
8262
| `Microsoft.Compute/sshPublicKeys/write` |
8363
| `Microsoft.Compute/sshPublicKeys/read` |
84-
| `Microsoft.Compute/sshPublicKeys /*/generateKeyPair/action` |
64+
| `Microsoft.Compute/sshPublicKeys/*/generateKeyPair/action` |
8565
| `Microsoft.Storage/storageAccounts/read` |
8666
| `Microsoft.Storage/storageAccounts/blobServices/read` |
8767
| `Microsoft.Storage/storageAccounts/blobServices/containers/read` |
8868
| `Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read` |
8969
| `Microsoft.Storage/storageAccounts/fileServices/read` |
9070
| `Microsoft.Storage/storageAccounts/fileServices/shares/read` |
9171

92-
9372
| Built-in roles for *user-assigned managed identities* |
9473
| ---------------------------------------------------- |
9574
| **Azure Center for SAP solutions service role** |
@@ -139,10 +118,9 @@ requires the following role or permissions.
139118

140119
## Install SAP software
141120

142-
To install SAP software, a *user* and *user-assigned managed identity* requires the following role
143-
or permissions.
121+
To install SAP software, a *user* and *user-assigned managed identity* require the following role or permissions.
144122

145-
| Built-in roles for *users* |
123+
| Built-in roles for *users* |
146124
| ------------------------- |
147125
| **Azure Center for SAP solutions administrator** |
148126

@@ -200,10 +178,9 @@ or permissions.
200178

201179
## Register and manage existing SAP system
202180

203-
To register an existing SAP system and manage that system with Azure Center for SAP solutions, a
204-
*user* or *user-assigned managed identity* requires the following role or permissions.
181+
To register an existing SAP system and manage that system with Azure Center for SAP solutions, a *user* or *user-assigned managed identity* requires the following role or permissions.
205182

206-
| Built-in roles for *users* |
183+
| Built-in roles for *users* |
207184
| ------------------------- |
208185
| **Azure Center for SAP solutions administrator** |
209186
| **Managed Identity Operator** |
@@ -243,12 +220,11 @@ To register an existing SAP system and manage that system with Azure Center for
243220
| `Microsoft.Resources/subscriptions/resourcegroups/deployments/*` |
244221
| `Microsoft.Resources/tags/*` |
245222

246-
## View VIS resources
223+
## View VIS resources
247224

248-
To view VIS resources, a *user* or *user-assigned managed identity* requires the following role or
249-
permissions.
225+
To view VIS resources, a *user* or *user-assigned managed identity* requires the following role or permissions.
250226

251-
| Built-in roles for *users* |
227+
| Built-in roles for *users* |
252228
| ------------------------- |
253229
| **Azure Center for SAP solutions reader** |
254230

@@ -271,18 +247,17 @@ permissions.
271247

272248
| Built-in roles for *user-assigned managed identities* |
273249
| ---------------------------------------------------- |
274-
| This scenario isn't applicable to *user-assigned managed identities*. |
250+
| This scenario doesn't apply to *user-assigned managed identities*. |
275251

276252
| Built-in permissions for *user-assigned managed identities* |
277253
| ---------------------------------------------------------- |
278-
| This scenario isn't applicable to *user-assigned managed identities*. |
254+
| This scenario doesn't apply to *user-assigned managed identities*. |
279255

280256
## Start SAP system
281257

282-
To start the SAP system from a VIS resource, a *user* and *user-assigned managed identity* requires
283-
the following role or permissions.
258+
To start the SAP system from a VIS resource, a *user* and *user-assigned managed identity* require the following role or permissions.
284259

285-
| Built-in roles for *users* |
260+
| Built-in roles for *users* |
286261
| ------------------------- |
287262
| **Azure Center for SAP solutions administrator** |
288263

@@ -303,10 +278,9 @@ the following role or permissions.
303278

304279
## Stop SAP system
305280

306-
To stop the SAP system from a VIS resource, a *user* and *user-assigned managed identity* requires
307-
the following role or permissions.
281+
To stop the SAP system from a VIS resource, a *user* and *user-assigned managed identity* require the following role or permissions.
308282

309-
| Built-in roles for *users* |
283+
| Built-in roles for *users* |
310284
| ------------------------- |
311285
| **Azure Center for SAP solutions administrator** |
312286

@@ -326,10 +300,10 @@ the following role or permissions.
326300
| `Microsoft.Compute/virtualMachines/instanceView/read` |
327301

328302
## Start SAP Central services instance
329-
To start the SAP Central services instance from a VIS resource, a *user* and *user-assigned managed
330-
identity* requires the following role or permissions.
331303

332-
| Built-in roles for *users* |
304+
To start the SAP Central services instance from a VIS resource, a *user* and *user-assigned managed identity* require the following role or permissions.
305+
306+
| Built-in roles for *users* |
333307
| ------------------------- |
334308
| **Azure Center for SAP solutions administrator** |
335309

@@ -349,10 +323,10 @@ identity* requires the following role or permissions.
349323
| `Microsoft.Compute/virtualMachines/instanceView/read` |
350324

351325
## Stop SAP Central services instance
352-
To stop the SAP Central services instance from a VIS resource, a *user* and *user-assigned managed
353-
identity* requires the following role or permissions.
354326

355-
| Built-in roles for *users* |
327+
To stop the SAP Central services instance from a VIS resource, a *user* and *user-assigned managed identity* require the following role or permissions.
328+
329+
| Built-in roles for *users* |
356330
| ------------------------- |
357331
| **Azure Center for SAP solutions administrator** |
358332

@@ -371,11 +345,11 @@ identity* requires the following role or permissions.
371345
| `Microsoft.Compute/virtualMachines/extensions/write` |
372346
| `Microsoft.Compute/virtualMachines/instanceView/read` |
373347

374-
## Start SAP Application server instance
375-
To start the SAP Application server instance from a VIS resource, a *user* and *user-assigned
376-
managed identity* requires the following role or permissions.
348+
## Start SAP application server instance
377349

378-
| Built-in roles for *users* |
350+
To start the SAP application server instance from a VIS resource, a *user* and *user-assigned managed identity* require the following role or permissions.
351+
352+
| Built-in roles for *users* |
379353
| ------------------------- |
380354
| **Azure Center for SAP solutions administrator** |
381355

@@ -394,11 +368,11 @@ managed identity* requires the following role or permissions.
394368
| `Microsoft.Compute/virtualMachines/extensions/write` |
395369
| `Microsoft.Compute/virtualMachines/instanceView/read` |
396370

397-
## Stop SAP Application server instance
398-
To stop the SAP Application server instance from a VIS resource, a *user* and *user-assigned managed
399-
identity* requires the following role or permissions.
371+
## Stop SAP application server instance
372+
373+
To stop the SAP application server instance from a VIS resource, a *user* and *user-assigned managed identity* require the following role or permissions.
400374

401-
| Built-in roles for *users* |
375+
| Built-in roles for *users* |
402376
| ------------------------- |
403377
| **Azure Center for SAP solutions administrator** |
404378

@@ -417,11 +391,11 @@ identity* requires the following role or permissions.
417391
| `Microsoft.Compute/virtualMachines/extensions/write` |
418392
| `Microsoft.Compute/virtualMachines/instanceView/read` |
419393

420-
## Start SAP HANA Database instance
421-
To start the SAP HANA Database instance from a VIS resource, a *user* and *user-assigned managed
422-
identity* requires the following role or permissions.
394+
## Start SAP HANA database instance
423395

424-
| Built-in roles for *users* |
396+
To start the SAP HANA database instance from a VIS resource, a *user* and *user-assigned managed identity* require the following role or permissions.
397+
398+
| Built-in roles for *users* |
425399
| ------------------------- |
426400
| **Azure Center for SAP solutions administrator** |
427401

@@ -440,11 +414,11 @@ identity* requires the following role or permissions.
440414
| `Microsoft.Compute/virtualMachines/extensions/write` |
441415
| `Microsoft.Compute/virtualMachines/instanceView/read` |
442416

443-
## Stop SAP HANA Database instance
444-
To stop the SAP HANA Database instance from a VIS resource, a *user* and *user-assigned managed
445-
identity* requires the following role or permissions.
417+
## Stop SAP HANA database instance
418+
419+
To stop the SAP HANA database instance from a VIS resource, a *user* and *user-assigned managed identity* require the following role or permissions.
446420

447-
| Built-in roles for *users* |
421+
| Built-in roles for *users* |
448422
| ------------------------- |
449423
| **Azure Center for SAP solutions administrator** |
450424

@@ -467,53 +441,52 @@ identity* requires the following role or permissions.
467441

468442
To view the cost analysis, a *user* requires the following role or permissions.
469443

470-
| Built-in roles for *users* |
444+
| Built-in roles for *users* |
471445
| ------------------------- |
472446
| **Cost Management Reader** |
473447

474448
| Minimum permissions for *users* |
475449
| ------------------------------- |
476-
| `Microsoft.Consumption/*/read**` |
450+
| `Microsoft.Consumption/*/read` |
477451
| `Microsoft.CostManagement/*/read` |
478-
| `Microsoft.Billing/billingPeriods/read` |
452+
| `Microsoft.Billing/billingPeriods/read` |
479453
| `Microsoft.Resources/subscriptions/read` |
480454
| `Microsoft.Resources/subscriptions/resourceGroups/read` |
481455
| `Microsoft.Billing/billingProperty/read` |
482456

483457
| Built-in roles for *user-assigned managed identities* |
484458
| ---------------------------------------------------- |
485-
| This scenario isn't applicable to *user-assigned managed identities*. |
459+
| This scenario doesn't apply to *user-assigned managed identities*. |
486460

487461
| Minimum permissions for *user-assigned managed identities* |
488462
| ---------------------------------------------------------- |
489-
| This scenario isn't applicable to *user-assigned managed identities*. |
463+
| This scenario doesn't apply to *user-assigned managed identities*. |
490464

491465
## View Quality Insights
492466

493467
To view Quality Insights, a *user* requires the following role or permissions.
494468

495-
| Built-in roles for *users* |
469+
| Built-in roles for *users* |
496470
| ------------------------- |
497471
| **Azure Center for SAP solutions reader** |
498472

499-
Minimum permissions for *users* |
473+
| Minimum permissions for *users* |
500474
| ------------------------------- |
501475
| None, except the minimum role assignment. |
502476

503477
| Built-in roles for *user-assigned managed identities* |
504478
| ---------------------------------------------------- |
505-
| This scenario isn't applicable to *user-assigned managed identities*. |
479+
| This scenario doesn't apply to *user-assigned managed identities*. |
506480

507481
| Minimum permissions for *user-assigned managed identities* |
508482
| ---------------------------------------------------------- |
509-
| This scenario isn't applicable to *user-assigned managed identities*. |
483+
| This scenario doesn't apply to *user-assigned managed identities*. |
510484

511485
## Set up Azure Monitor for SAP solutions
512486

513-
To set up Azure Monitor for SAP solutions for your SAP resources, a *user* requires the following
514-
role or permissions.
487+
To set up Azure Monitor for SAP solutions for your SAP resources, a *user* requires the following role or permissions.
515488

516-
| Built-in roles for *users* |
489+
| Built-in roles for *users* |
517490
| ------------------------- |
518491
| **Contributor** |
519492

@@ -523,18 +496,17 @@ role or permissions.
523496

524497
| Built-in roles for *user-assigned managed identities* |
525498
| ---------------------------------------------------- |
526-
| This scenario isn't applicable to *user-assigned managed identities*. |
499+
| This scenario doesn't apply to *user-assigned managed identities*. |
527500

528501
| Minimum permissions for *user-assigned managed identities* |
529502
| ---------------------------------------------------------- |
530-
| This scenario isn't applicable to *user-assigned managed identities*. |
503+
| This scenario doesn't apply to *user-assigned managed identities*. |
531504

532505
## Delete VIS resource
533506

534-
To delete a VIS resource, a *user* or *user-assigned managed identity* requires the following role
535-
or permissions.
507+
To delete a VIS resource, a *user* or *user-assigned managed identity* requires the following role or permissions.
536508

537-
| Built-in roles for *users* |
509+
| Built-in roles for *users* |
538510
| ------------------------- |
539511
| **Azure Center for SAP solutions administrator** |
540512

@@ -548,12 +520,12 @@ or permissions.
548520

549521
| Built-in roles for *user-assigned managed identities* |
550522
| ---------------------------------------------------- |
551-
| This scenario isn't applicable to *user-assigned managed identities*. |
523+
| This scenario doesn't apply to *user-assigned managed identities*. |
552524

553525
| Minimum permissions for *user-assigned managed identities* |
554526
| ---------------------------------------------------------- |
555-
| This scenario isn't applicable to *user-assigned managed identities*. |
527+
| This scenario doesn't apply to *user-assigned managed identities*. |
556528

557-
## Next steps
529+
## Related content
558530

559531
- [Manage VIS resources in Azure Center for SAP solutions](manage-virtual-instance.md)

0 commit comments

Comments
 (0)