An IAM role is created in the Azure console which is required for the Controller and Manager communication. With the help of the IAM role, the Controller retrieves information about users from the Manager.
Note
You must assign the IAM role to the Local Controller or External Controller instance for the Controller and Manager communication. In case of Local Controller, you must assign the IAM role to the Manager instance itself.
To create a IAM role in Azure, perform the following steps:
Task
- Click All services. Under Identity category, click Managed Identity.
-
Click
+ Add.
The Create User Assigned Managed Identity window along with the Basics tab opens.
-
On the
Basics tab, enter the following details:
Option Definition PROJECT DETAILS Subscription - The subscription linked with your Azure account is selected by default. If you have multiple subscription accounts, select the subscription account in which you would like to launch the Manager virtual machine.
Resource group
- Create new - You can create a new resource group to be protected.
- Use existing - Select a resource group from the existing resource groups to be protected.
INSTANCE DETAILS Region - Select the region where the managed identity must be created.
Name - Type a name for the User Assigned Managed Identity.
Note
The User Assigned Managed Identity name should not exceed 25 characters.
Note
Azure validates the information you enter and a green tick appears against the fields where you enter details.
-
Click
Next: Tags >.
The Tags tab opens. On this tab, you can categorize resources by applying a tag name and value to multiple resources and resource groups.
-
Click
Next: Review + create >.
The Review + create tab opens. Validate the summary details which contains all the parameters selected. Make sure the validation is successful.
-
Click
Create.
The user assigned managed identity is created.
-
Go to
All Services → Identity → Managed Identity and select the newly created User assigned managed identity.
A page with details of the selected user assigned managed identity opens.
-
Click
Access control (IAM).
The Access control (IAM) window opens.
Note
You require Owner access to add permissions to the registered application.
- Click Add role assignments.
-
In the
Add role assignments window, enter the following details:
Option Definition Role Select a pre-defined role from the drop-down. The minimum required role is Reader. You can select Contributor or Owner as well. Assign access to Select User, group or service principal. Select Search and select the user based managed identity for which the role needs to be assigned. - Click Save.