How Do I Configure the Permissions Required for Collecting Details of Azure Containers?
This section describes how to configure the permissions required for using MgC to collect details about Azure container resources. The application that the collection credential belongs to must have the following information in the involved resource group and subscription:
- Microsoft.ClassicCompute/virtualMachines/read
- Microsoft.Insights/MetricDefinitions/Read
- Microsoft.Management/getEntities/action
Procedure
- Sign in to the Azure portal.
- In the upper part of the page, enter Resource groups in the search box and select Resource groups.
- In the resource group list, click the resource group that contains your Azure Kubernetes Service (AKS) resources.
- In the navigation pane on the left, choose Access control (IAM). On the Check access tab, click Add role assignment.
- Select Reader and click Next.
- Click Select members. In the dialog box displayed on the right, search for and click the application name (that the collection credential belongs to).
- Click Select to add it to the member list.
- Click Review + assign.
- After confirming that the role and member are correct, click Review+ assign to configure permissions for the application in the resource group.
- In the upper part of the page, search for and select Subscriptions.
- In the subscription list, click the name of the subscription that contains your AKS resources.
- Configure permissions for the application in the subscription by referring to Step 4 to Step 9.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot