How to grant a system assigned managed identity an access to a workspace

Jean-Florent VOELKER 10 Reputation points
2023-03-24T14:34:46.1633333+00:00

I select "system assigned managed identity" in the "Managed identity" panel of my compute cluster.

But when I go to the AML Workspace panel to gran READER acces to this managed Identity, I can not find it among the managed identity.

I have to set an "User assigned managed identity" for my compute cluster and then I can find this kind of managed identity in the AML Workspace panel and grant the READER Access.

Why can I not retrieve the system assigned managed identity ?

The compute cluster is in another region than the one of the workspace. Is this the reason ?

Azure Machine Learning
Azure Machine Learning
An Azure machine learning service for building and deploying models.
2,583 questions
{count} vote

4 answers

Sort by: Most helpful
  1. AshokPeddakotla-MSFT 27,976 Reputation points
    2023-03-27T06:28:32.02+00:00

    Jean-Florent VOELKER Welcome to Microsoft Q&A forum!

    Which documentation are you following?

    Please note that, Azure Machine Learning compute clusters support only one system-assigned identity or multiple user-assigned identities, not both concurrently.

    I would suggest you, check the documentation Set up authentication between Azure Machine Learning and other services for steps and let us know if that helps.


  2. Poda Csanad 0 Reputation points
    2024-01-23T16:59:09.66+00:00

    @Jean-Florent VOELKER please do let me know if you managed to figure this one out as I'm struggling with the same...

    0 comments No comments

  3. Jean-Florent VOELKER 10 Reputation points
    2024-01-25T09:08:47.95+00:00

    Hi, I found a solution.
    I created an UserGroup whose I granted the appropriate role (READER) and then I assign my system assigned managed identity to these group.

    Hope it helps you

    0 comments No comments

  4. Jean-Florent VOELKER 10 Reputation points
    2024-01-25T09:09:07.4733333+00:00

    Hi, I found a solution.
    I created an UserGroup whose I granted the appropriate role (READER) and then I assign my system assigned managed identity to these group.

    Hope it helps you

    0 comments No comments