At a Glance
Goals
- You know how to grant permissions to new people within a Subscription.
Prerequisites
- You must already be able to access a Subscription.
- You have activated the appropriate role that allows you to grant permissions to others.
References
Note
This guide was created with the language setting set to English. Therefore, the screenshots shown may differ from your device if you have a different language set.
Permanent Role
Before you can assign a role, you must first navigate to the resource to which the permission should be granted. In this guide, additional rights are granted directly on the Subscription.
-
Log in to the Portal.
-
Navigate to your Subscription.
-
Click on
Access control (IAM)in the left menu. -
Click the
Addbutton and thenAdd role assignment. -
In the
Roletab, select the designated role. In this example, another user is granted access to all resources within a Subscription. The role can be found underPrivileged administrator roleswith the nameUnibe-Application-Owner (mg-unibe). ClickNext. -
In the
Memberstab, select the user. ClickSelect Membersand choose the person in the popup. ClickNext. -
In the
Assignment Typetab, you can set additional conditions for the role assignment. In this example, we assign the role permanently. UnderAssignment type, selectActiveand underAssignment duration, selectPermanent. ClickReview + assign. -
Review the details and click
Review + assign.
Role On Request
In the previous example, a permanent permission was granted. You can also assign a role with additional conditions:
- You can assign a role for a certain period of time.
- You can assign a role so that it must be requested first (similar to the PIM group for Subscription owners).
Important
You cannot assign a role on request to service accounts.
-
Log in to the Portal.
-
Navigate to your Subscription.
-
Click on
Access control (IAM)in the left menu. -
Click the
Addbutton and thenAdd role assignment. -
In the
Roletab, select the designated role. In this example, another user is granted access to all resources within a Subscription. The role can be found underPrivileged administrator roleswith the nameUnibe-Application-Owner (mg-unibe). ClickNext. -
In the
Memberstab, select the user. ClickSelect Membersand choose the person in the popup. ClickNext. -
In the
Assignment Typetab, you can set additional conditions for the role assignment. In this example, we assign the role on request. UnderAssignment type, selectEligible (Recommended)and underAssignment duration, selectTime bound. Choose the start and end time for the role and clickReview + assign. -
Review the details and click
Review + assign.
Requesting a Role
For instructions on requesting a role, see this article.









