Lighthouse - Deploy a Policy that can be remediated with Managed Identity

bsonnek 51 Reputation points
2021-10-15T18:35:06.057+00:00

Can someone confirm if I'm understanding the Managed Identity part of Azure policy remediation from this article?
https://video2.skills-academy.com/en-us/azure/lighthouse/how-to/deploy-policy-remediation#create-a-user-who-can-assign-roles-to-a-managed-identity-in-the-customer-tenant

Do we actually need to create a managed identity inside the customer's subscription to use when we remediate a policy?
OR does the remediation create a managed identity in the process to use for remediation?

I just want to make sure we don't make this more difficult than it needs to be by adding a managed identity to all the existing customer subscriptions we manage in lighthouse.

Currently, the only way I've been able to get an assigned policy to remediate in a customer's subscription, from lighthouse, is to use a "user assigned" managed identity that I manually created inside the customer's subscription.
Am I missing something here, or is this exactly how this is supposed to work?
Thank you in advance!

Azure Lighthouse
Azure Lighthouse
An Azure service that provides secure managed services and access control for partners and customers.
71 questions
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
821 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,365 questions
{count} votes