Request: Less Privileged NMM Updates

Currently, NMM Updates say they require an Entra Global Administrator and an Azure Subscription owner in order to update from one revision to another. 

From a security stance, that really limits the amount of team members able to perform these updates. Are there a collection of lesser-privileged Entra or Azure role assignments that can be used to perform the updates? Like Cloud App Administrator in Entra, or Owner at the resource group level, or even a custom Azure role that can be assigned to people that need to perform updates?

8

Comments (3 comments)

0
Avatar
Carl Long
Thank you for your feature request—your input helps shape our roadmap.

Next steps:
     • We will review your request and update its status as it moves through the evaluation process.
     • If we need more details, we'll reach out in the comments.

We also welcome additional feedback and votes from the community.
1
Avatar
John Tokash

I like the idea - it may be a bit challenging to implement on their side, but it gets my vote to at least explore and see what the level of effort would be.     That said, as a workaround, have you considered leveraging PIM to grant the elevated access temporarily?  It probably isn't the ‘right’ solution, because they still get unnecessary access to the partner tenant, unnecessary outside the scope of the upgrade that is.  I've heard from other partners at NerdioCon that some have created a designated account for the updates, and access to the credentials (via unrelated vault) is managed for ‘granting’ and ‘revoking’ that access as needed.  

You are very right thought, those are pretty high ranking roles.    In our case, they aren't frequent enough to warrant delegating the update out to other team members, so the team that holds the access in the first place - does the updates.

2
Avatar
Martijn Van Braeckel

Please sign in to leave a comment.