What roles is sufficient for The Network Team member to setup and configure Azure ExpressRoute, VNETs, UDR, Firewall, AppGW and NSGs in all of my Subscriptions?

EnterpriseArchitect 5,376 Reputation points
2021-05-18T06:33:29.427+00:00

Hi All,

I need to grant a specific team of external contractor the capability to create, manage and troubleshoot: Azure ExpressRoute, UDR, AppGw, VNETs, Firewall and NSGs.

Which roles should I grant for the Azure AD group under the Privileged Identity Management and Manage > Roles?

Network Contributor: https://video2.skills-academy.com/en-us/azure/role-based-access-control/built-in-roles#network-contributor
Network Administrator: https://video2.skills-academy.com/en-us/azure/active-directory/roles/permissions-reference#network-administrator

Thank you in advance.

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,873 questions
Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,427 questions
Azure Network Watcher
Azure Network Watcher
An Azure service that is used to monitor, diagnose, and gain insights into network performance and health.
169 questions
Microsoft Entra
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 36,846 Reputation points Microsoft Employee
    2021-05-18T23:29:00.44+00:00

    Hi @EnterpriseArchitect ,

    As you mentioned, you need at least a network contributor role to manage VNETs and NSGs. For firewalls depending on what you need to do you may need something more privileged like a Security Administrator or a Global Admin, since part of the features in Azure Firewall involve setting up or denying access for particular users.

    You could look into custom roles but depending on what you need to do for user access controls you may end up needing higher privilege. For most of the things you mentioned Network Contributor will be enough, though.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.