Can a customer's same resource group be managed by multiple MSSP in Azure Lighthouse?

Wesley 46 Reputation points
2025-04-17T05:27:51.0233333+00:00

A customer is currently migrating from another MSSP Lighthouse to our Lighthouse. I'm wondering how to make the migration smoother. It would be great if one customer could subscribe to multiple Lighthouses. If not, they will need to migrate out and then in. Any help with this would be great. Thanks

Azure Lighthouse
Azure Lighthouse
An Azure service that provides secure managed services and access control for partners and customers.
92 questions
0 comments No comments
{count} votes

Accepted answer
  1. Ashok Gandhi Kotnana 7,745 Reputation points Microsoft External Staff Moderator
    2025-04-17T09:34:54.47+00:00

    Hi @Wesley,
    In Additions to the above response from @Abiola Akinbade

    Review the current Lighthouse delegation for MSSP A:

     Check the role assigned (e.g., Reader, Contributor, Owner): If the assigned role is Reader, MSSP A will only have read-only access to the resources.

     Verify the role being granted to MSSP B during delegation: When delegating to MSSP B, ensure that the appropriate RBAC role (such as Contributor or Owner) is assigned, based on the level of control you want to give.

     By managing these roles correctly, you can ensure MSSP A retains limited (read-only), while MSSP B is given full control to manage the environment.

    Please let me know if you face any challenge here, I can help you to resolve this issue further

    Please provide your valuable comments User's image

    Please do not forget to "Accept the answer” and “upvote it” wherever the information provided helps you, this can be beneficial to other community members.it would be greatly appreciated and helpful to others.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Abiola Akinbade 27,530 Reputation points Moderator
    2025-04-17T05:58:10.34+00:00

    Yes, a Customer's Resource Group Can Be Managed by Multiple MSSPs in Azure Lighthouse.

    RBAC, upon which Lighthouse relies, allows multiple role assignments on the same scope. Therefore, a customer can create separate delegations for the same resource group or subscription to different service provider tenants. Each delegation is independent.

    See: https://learn.microsoft.com/en-us/azure/lighthouse/how-to/view-manage-service-providers

    You can mark it 'Accept Answer' and 'Upvote' if this helped you

    Regards,

    Abiola


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.