Skip to content
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.

Commit 5b2efc9

Browse files
committedMar 12, 2022
Update RBAC role assignment steps - batch 2
1 parent f10b1f3 commit 5b2efc9

18 files changed

+91
-52
lines changed
 
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.

‎articles/migrate/tutorial-discover-aws.md

Lines changed: 15 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: vibansa
66
ms.manager: abhemraj
77
ms.topic: tutorial
88
ms.date: 03/11/2021
9-
ms.custom: mvc
9+
ms.custom: mvc, subject-rbac-steps
1010
#Customer intent: As a server admin I want to discover my AWS instances.
1111
---
1212

@@ -53,19 +53,26 @@ If you just created a free Azure account, you're the owner of your subscription.
5353

5454
![Image of Search box to search for the Azure subscription.](./media/tutorial-discover-aws/search-subscription.png)
5555

56-
2. In the **Subscriptions** page, select the subscription in which you want to create a project.
57-
3. In the subscription, select **Access control (IAM)** > **Check access**.
58-
4. In **Check access**, search for the relevant user account.
59-
5. In **Add a role assignment**, click **Add**.
56+
1. In the **Subscriptions** page, select the subscription in which you want to create a project.
6057

61-
![Screenshot of process to search for a user account to check access and assign a role.](./media/tutorial-discover-aws/azure-account-access.png)
58+
1. Select **Access control (IAM)**.
6259

63-
6. In **Add role assignment**, select the Contributor or Owner role, and select the account (azmigrateuser in our example). Then click **Save**.
60+
1. Select **Add** > **Add role assignment** to open the **Add role assignment** page.
6461

65-
![Screenshot of the Add Role assignment page to assign a role to the account.](./media/tutorial-discover-aws/assign-role.png)
62+
1. Assign the following role. For detailed steps, see [Assign Azure roles using the Azure portal](../role-based-access-control/role-assignments-portal.md).
63+
64+
| Setting | Value |
65+
| --- | --- |
66+
| Role | Contributor or Owner |
67+
| Assign access to | User |
68+
| Members | azmigrateuser |
69+
70+
![Add role assignment page in Azure portal.](../../includes/role-based-access-control/media/add-role-assignment-page.png)
6671

6772
1. To register the appliance, your Azure account needs **permissions to register Azure Active Directory apps.**
73+
6874
1. In Azure portal, navigate to **Azure Active Directory** > **Users** > **User Settings**.
75+
6976
1. In **User settings**, verify that Azure AD users can register applications (set to **Yes** by default).
7077

7178
![Image to Verify in User Settings that users can register Active Directory apps](./media/tutorial-discover-aws/register-apps.png)

‎articles/migrate/tutorial-discover-gcp.md

Lines changed: 15 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: vibansa
66
ms.manager: abhemraj
77
ms.topic: tutorial
88
ms.date: 03/13/2021
9-
ms.custom: mvc
9+
ms.custom: mvc, subject-rbac-steps
1010
#Customer intent: As a server admin I want to discover my GCP instances.
1111
---
1212

@@ -53,19 +53,26 @@ If you just created a free Azure account, you're the owner of your subscription.
5353

5454
![Screenshot of Search box to search for the Azure subscription.](./media/tutorial-discover-gcp/search-subscription.png)
5555

56-
2. In the **Subscriptions** page, select the subscription in which you want to create a project.
57-
3. In the subscription, select **Access control (IAM)** > **Check access**.
58-
4. In **Check access**, search for the relevant user account.
59-
5. In **Add a role assignment**, click **Add**.
56+
1. In the **Subscriptions** page, select the subscription in which you want to create a project.
6057

61-
![Image to Search for a user account to check access and assign a role.](./media/tutorial-discover-gcp/azure-account-access.png)
58+
1. Select **Access control (IAM)**.
6259

63-
6. In **Add role assignment**, select the Contributor or Owner role, and select the account (azmigrateuser in our example). Then click **Save**.
60+
1. Select **Add** > **Add role assignment** to open the **Add role assignment** page.
6461

65-
![Screenshot of Add Role assignment page to assign a role to the account.](./media/tutorial-discover-gcp/assign-role.png)
62+
1. Assign the following role. For detailed steps, see [Assign Azure roles using the Azure portal](../role-based-access-control/role-assignments-portal.md).
63+
64+
| Setting | Value |
65+
| --- | --- |
66+
| Role | Contributor or Owner |
67+
| Assign access to | User |
68+
| Members | azmigrateuser |
69+
70+
![Add role assignment page in Azure portal.](../../includes/role-based-access-control/media/add-role-assignment-page.png)
6671

6772
1. To register the appliance, your Azure account needs **permissions to register Azure Active Directory apps.**
73+
6874
1. In Azure portal, navigate to **Azure Active Directory** > **Users** > **User Settings**.
75+
6976
1. In **User settings**, verify that Azure AD users can register applications (set to **Yes** by default).
7077

7178
![Verify in User Settings that users can register Active Directory apps.](./media/tutorial-discover-gcp/register-apps.png)

‎articles/migrate/tutorial-discover-hyper-v.md

Lines changed: 16 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: vibansa
66
ms.manager: abhemraj
77
ms.topic: tutorial
88
ms.date: 11/12/2021
9-
ms.custom: mvc
9+
ms.custom: mvc, subject-rbac-steps
1010
#Customer intent: As a Hyper-V admin, I want to discover my on-premises servers on Hyper-V.
1111
---
1212

@@ -52,24 +52,31 @@ If you just created a free Azure account, you're the owner of your subscription.
5252

5353
![Screenshot of Search box to search for the Azure subscription.](./media/tutorial-discover-hyper-v/search-subscription.png)
5454

55-
2. In the **Subscriptions** page, select the subscription in which you want to create a project.
56-
3. In the subscription, select **Access control (IAM)** > **Check access**.
57-
4. In **Check access**, search for the relevant user account.
58-
5. In **Add a role assignment**, click **Add**.
55+
1. In the **Subscriptions** page, select the subscription in which you want to create a project.
5956

60-
![Screenshot of Search for a user account to check access and assign a role.](./media/tutorial-discover-hyper-v/azure-account-access.png)
57+
1. Select **Access control (IAM)**.
6158

62-
6. In **Add role assignment**, select the Contributor or Owner role, and select the account (azmigrateuser in our example). Then click **Save**.
59+
1. Select **Add** > **Add role assignment** to open the **Add role assignment** page.
6360

64-
![Screenshot of the Add Role assignment page to assign a role to the account.](./media/tutorial-discover-hyper-v/assign-role.png)
61+
1. Assign the following role. For detailed steps, see [Assign Azure roles using the Azure portal](../role-based-access-control/role-assignments-portal.md).
62+
63+
| Setting | Value |
64+
| --- | --- |
65+
| Role | Contributor or Owner |
66+
| Assign access to | User |
67+
| Members | azmigrateuser |
68+
69+
![Add role assignment page in Azure portal.](../../includes/role-based-access-control/media/add-role-assignment-page.png)
6570

6671
1. To register the appliance, your Azure account needs **permissions to register Azure Active Directory apps.**
72+
6773
1. In the Azure portal, navigate to **Azure Active Directory** > **Users** > **User Settings**.
74+
6875
1. In **User settings**, verify that Azure AD users can register applications (set to **Yes** by default).
6976

7077
![Verify in User Settings that users can register Active Directory apps.](./media/tutorial-discover-hyper-v/register-apps.png)
7178

72-
9. In case the 'App registrations' settings is set to 'No', request the tenant/global admin to assign the required permission. Alternately, the tenant/global admin can assign the **Application Developer** role to an account to allow the registration of Azure Active Directory App. [Learn more](../active-directory/fundamentals/active-directory-users-assign-role-azure-portal.md).
79+
1. In case the 'App registrations' settings is set to 'No', request the tenant/global admin to assign the required permission. Alternately, the tenant/global admin can assign the **Application Developer** role to an account to allow the registration of Azure Active Directory App. [Learn more](../active-directory/fundamentals/active-directory-users-assign-role-azure-portal.md).
7380

7481
## Prepare Hyper-V hosts
7582

‎articles/migrate/tutorial-discover-import.md

Lines changed: 16 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@ ms.author: vivikram
66
ms.manager: abhemraj
77
ms.topic: tutorial
88
ms.date: 09/14/2020
9+
ms.custom: subject-rbac-steps
910
#Customer intent: As a server admin, I want to discover servers using an imported CSV file.
1011
---
1112

@@ -56,19 +57,25 @@ If you just created a free Azure account, you're the owner of your subscription.
5657

5758
![Search box to search for the Azure subscription](./media/tutorial-discover-import/search-subscription.png)
5859

59-
2. In the **Subscriptions** page, select the subscription in which you want to create an Azure Migrate project.
60-
3. In the subscription, select **Access control (IAM)** > **Check access**.
61-
4. In **Check access**, search for the relevant user account.
62-
5. In **Add a role assignment**, select **Add**.
60+
1. In the **Subscriptions** page, select the subscription in which you want to create an Azure Migrate project.
6361

64-
![Search for a user account to check access and assign a role](./media/tutorial-discover-import/azure-account-access.png)
62+
1. Select **Access control (IAM)**.
6563

66-
6. In **Add role assignment**, select the Contributor or Owner role, and select the account (azmigrateuser in our example). Then select **Save**.
64+
1. Select **Add** > **Add role assignment** to open the **Add role assignment** page.
6765

68-
![Opens the Add Role assignment page to assign a role to the account](./media/tutorial-discover-import/assign-role.png)
66+
1. Assign the following role. For detailed steps, see [Assign Azure roles using the Azure portal](../role-based-access-control/role-assignments-portal.md).
6967

70-
7. In the portal, search for users, and under **Services**, select **Users**.
71-
8. In **User settings**, verify that Azure AD users can register applications (set to **Yes** by default).
68+
| Setting | Value |
69+
| --- | --- |
70+
| Role | Contributor or Owner |
71+
| Assign access to | User |
72+
| Members | azmigrateuser |
73+
74+
![Add role assignment page in Azure portal.](../../includes/role-based-access-control/media/add-role-assignment-page.png)
75+
76+
1. In the portal, search for users, and under **Services**, select **Users**.
77+
78+
1. In **User settings**, verify that Azure AD users can register applications (set to **Yes** by default).
7279

7380
![Verify in User Settings that users can register Active Directory apps](./media/tutorial-discover-import/register-apps.png)
7481

‎articles/migrate/tutorial-discover-physical.md

Lines changed: 14 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: vibansa
66
ms.manager: abhemraj
77
ms.topic: tutorial
88
ms.date: 11/12/2021
9-
ms.custom: mvc
9+
ms.custom: mvc, subject-rbac-steps
1010
#Customer intent: As a server admin I want to discover my on-premises server inventory.
1111
---
1212

@@ -55,24 +55,29 @@ If you just created a free Azure account, you're the owner of your subscription.
5555

5656
![Screenshot of search box to search for the Azure subscription.](./media/tutorial-discover-physical/search-subscription.png)
5757

58-
2. In the **Subscriptions** page, select the subscription in which you want to create the project.
59-
3. In the subscription, select **Access control (IAM)** > **Check access**.
60-
4. In **Check access**, search for the relevant user account.
61-
5. In **Add a role assignment**, click **Add**.
58+
1. Select **Access control (IAM)**.
6259

63-
![Screenshot of searching for a user account to check access and assign a role.](./media/tutorial-discover-physical/azure-account-access.png)
60+
1. Select **Add** > **Add role assignment** to open the **Add role assignment** page.
6461

65-
6. In **Add role assignment**, select the Contributor or Owner role, and select the account (azmigrateuser in our example). Then click **Save**.
62+
1. Assign the following role. For detailed steps, see [Assign Azure roles using the Azure portal](../role-based-access-control/role-assignments-portal.md).
6663

67-
![Screenshot of the Add Role assignment page to assign a role to the account.](./media/tutorial-discover-physical/assign-role.png)
64+
| Setting | Value |
65+
| --- | --- |
66+
| Role | Contributor or Owner |
67+
| Assign access to | User |
68+
| Members | azmigrateuser |
69+
70+
![Add role assignment page in Azure portal.](../../includes/role-based-access-control/media/add-role-assignment-page.png)
6871

6972
1. To register the appliance, your Azure account needs **permissions to register Azure Active Directory apps.**
73+
7074
1. In Azure portal, navigate to **Azure Active Directory** > **Users** > **User Settings**.
75+
7176
1. In **User settings**, verify that Azure AD users can register applications (set to **Yes** by default).
7277

7378
![Verify in User Settings that users can register Active Directory apps.](./media/tutorial-discover-physical/register-apps.png)
7479

75-
9. In case the 'App registrations' settings is set to 'No', request the tenant/global admin to assign the required permission. Alternately, the tenant/global admin can assign the **Application Developer** role to an account to allow the registration of Azure Active Directory App. [Learn more](../active-directory/fundamentals/active-directory-users-assign-role-azure-portal.md).
80+
1. In case the 'App registrations' settings is set to 'No', request the tenant/global admin to assign the required permission. Alternately, the tenant/global admin can assign the **Application Developer** role to an account to allow the registration of Azure Active Directory App. [Learn more](../active-directory/fundamentals/active-directory-users-assign-role-azure-portal.md).
7681

7782
## Prepare physical servers
7883

‎articles/migrate/tutorial-discover-vmware.md

Lines changed: 15 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: vibansa
66
ms.manager: abhemraj
77
ms.topic: tutorial
88
ms.date: 11/12/2021
9-
ms.custom: mvc
9+
ms.custom: mvc, subject-rbac-steps
1010
#Customer intent: As an VMware admin, I want to discover my on-premises servers running in a VMware environment.
1111
---
1212

@@ -57,24 +57,30 @@ To set Contributor or Owner permissions in the Azure subscription:
5757
:::image type="content" source="./media/tutorial-discover-vmware/search-subscription.png" alt-text="Screenshot that shows how to search for an Azure subscription in the search box.":::
5858

5959
1. In **Subscriptions**, select the subscription in which you want to create a project.
60-
1. In the left menu, select **Access control (IAM)**.
61-
1. On the **Check access** tab, under **Check access**, search for the user account you want to use.
62-
1. In the **Add a role assignment** pane, select **Add**.
6360

64-
:::image type="content" source="./media/tutorial-discover-vmware/azure-account-access.png" alt-text="Screenshot that shows how to search for a user account to check access and add a role assignment.":::
65-
66-
1. In **Add role assignment**, select the Contributor or Owner role, and then select the account. Select **Save**.
61+
1. Select **Access control (IAM)**.
62+
63+
1. Select **Add** > **Add role assignment** to open the **Add role assignment** page.
64+
65+
1. Assign the following role. For detailed steps, see [Assign Azure roles using the Azure portal](../role-based-access-control/role-assignments-portal.md).
6766

68-
:::image type="content" source="./media/tutorial-discover-vmware/assign-role.png" alt-text="Screenshot that shows the Add role assignment page to assign a role to the account.":::
67+
| Setting | Value |
68+
| --- | --- |
69+
| Role | Contributor or Owner |
70+
| Assign access to | User |
71+
| Members | azmigrateuser |
72+
73+
:::image type="content" source="../../includes/role-based-access-control/media/add-role-assignment-page.png" alt-text="Add role assignment page in Azure portal.":::
6974

7075
To give the account the required permissions to register Azure AD apps:
7176

7277
1. In the portal, go to **Azure Active Directory** > **Users** > **User Settings**.
78+
7379
1. In **User settings**, verify that Azure AD users can register applications (set to **Yes** by default).
7480

7581
:::image type="content" source="./media/tutorial-discover-vmware/register-apps.png" alt-text="Screenshot that shows verifying user setting to register apps.":::
7682

77-
9. If **App registrations** is set to **No**, request the tenant or global admin to assign the required permissions. Alternately, the tenant or global admin can assign the Application Developer role to an account to allow Azure AD app registration by users. [Learn more](../active-directory/fundamentals/active-directory-users-assign-role-azure-portal.md).
83+
1. If **App registrations** is set to **No**, request the tenant or global admin to assign the required permissions. Alternately, the tenant or global admin can assign the Application Developer role to an account to allow Azure AD app registration by users. [Learn more](../active-directory/fundamentals/active-directory-users-assign-role-azure-portal.md).
7884

7985
## Prepare VMware
8086

0 commit comments

Comments
 (0)
Please sign in to comment.