MSP Azure Lighthouse - cannot access Azure Policies deployed at Management Group Level

Joseph Attard 20 Reputation points
2023-02-17T20:44:53.3133333+00:00

Hi,

 

We're an MSP company that provides Azure services to other companies. We're using Azure Lighthouse to allow team members to access the client's Azure Subscriptions. Currently, we've ran into an issue that when Azure Policies are deployed at a Management Group level, we don't have visibility to them. The reason is that Azure Lighthouse gives us access at the Subscription level and not a Management Group level. If Azure Policy is deployed at a Management Group level, we won't be able to see or edit it.

 

Has anyone else encountered this?

Does anyone know how to access Management Groups through Azure Lighthouse? Or if there is another way to configure this for a Service Provider?

 

Regards,

Joseph

Azure Lighthouse
Azure Lighthouse
An Azure service that provides secure managed services and access control for partners and customers.
71 questions
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
821 questions
{count} votes

Accepted answer
  1. Luke Murray 10,636 Reputation points MVP
    2023-02-20T07:42:30.8466667+00:00

    Hi, Jospeh

    Yes, unfortunately, delegation isn't done at a Management Group level.

    You can deploy a policy with Contributor or Owner rights to the Management Group - to onboard all subscriptions: You can deploy a policy with Contributor or Owner rights to the Management Group - to onboard all new subscriptions: https://video2.skills-academy.com/en-us/azure/lighthouse/how-to/onboard-management-group - but you won't have control of the management groups itself.

    There is a vote for assignment: https://feedback.azure.com/d365community/idea/db5090d8-f824-ec11-b6e6-000d3a4f0da0

    It could be worth a look at Policy as Code - as an MSP, you could stand up a Service Principal in your customers tenant and use that to deploy policies to your management group: https://video2.skills-academy.com/en-us/azure/governance/policy/concepts/policy-as-code.

    0 comments No comments

0 additional answers

Sort by: Most helpful