Azure AD Roles / Privileges Required to Create an Azure Resource with System Managed Identity

Taranjeet Malik 451 Reputation points
2024-07-16T03:09:47.4233333+00:00

Hi

Are there any specific Azure AD roles / privileges required when creating an Azure Resource with a System Assigned Managed Identity? For example, when deploying an API Management instance using Azure DevOps (Service Connection) - if the APIM is being created with a System Assigned Managed Identity.

Thanks

Taranjeet Singh

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,469 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Stanislav Zhelyazkov 22,101 Reputation points MVP
    2024-07-16T05:43:19.0933333+00:00

    Hi,

    You do not need any special permissions to create resource with system assigned managed identity besides the permissions to create the resource. For example to create API Management instance you will need API Management Service Contributor or higher role.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments