我们目前正在查看Azure的用户访问权限。我们想审查并进一步完善Azure随附的现有/内置角色。例如,在某些情况下,贡献者的访问可能有点太多。具体而言,以下是Ware试图创建的两个角色:
是否有任何建议或角色可以帮助实现上述内容?
谢谢
We are currently review our user access permission for Azure. We want to review and further refine the existing/built-in roles that came with Azure. For example, the Contributor access may be a bit too much in some instance. Specifically, below are two roles ware are trying to create:
-
DEVELOPER: Currently our Developers are assigned Contributor by default. The issue here is that this gives them the ability the create/delete resources as will. Resources are typically pre-created by the Cloud Team. We want to limit that. Ideally, we want to give them the ability to configure resources and start/stop rescues.
-
OPERATOR: This is for our IT folks who need to review resources and start and restart resources. Similar to the Developer roles above, they don't need to create/delete resources.
Any suggestions or roles examples that can help achieve the above?
Thanks
发布评论
评论(1)
您可以使用 azure自定义角色 。看一下 azure tutorarior 和。
You can use Azure Custom Roles. Take a look at the Azure Portal Tutorial and the Azure resource provider operations.