An IAM role is created in the Azure console which is required for the Controller and Manager communication. With the help of the IAM role, the Controller retrieves information about users from the Manager.
Note
You must assign the IAM role to the Local Controller or External Controller instance for the Controller and Manager communication. In case of Local Controller, you must assign the IAM role to the Manager instance itself.
To create a IAM role in Azure, perform the following steps:
Click All services. Under Identity category, click Managed Identity.
Click + Add.
The Create User Assigned Managed Identity window along with the Basics tab opens.
On the Basics tab, enter the following details:
Option
Definition
PROJECT DETAILS
Subscription - The subscription linked with your Azure account is selected by default. If you have multiple subscription accounts, select the subscription account in which you would like to launch the Manager virtual machine.
Resource group
Create new - You can create a new resource group to be protected.
Use existing - Select a resource group from the existing resource groups to be protected.
INSTANCE DETAILS
Region - Select the region where the managed identity must be created.
Name - Type a name for the User Assigned Managed Identity.
Note
The User Assigned Managed Identity name should not exceed 25 characters.
Note
Azure validates the information you enter and a green tick appears against the fields where you enter details.
Click Next: Tags >.
The Tags tab opens. On this tab, you can categorize resources by applying a tag name and value to multiple resources and resource groups.
Click Next: Review + create >.
The Review + create tab opens. Validate the summary details which contains all the parameters selected. Make sure the validation is successful.
Click Create.
The user assigned managed identity is created.
Go to All Services → Identity → Managed Identity and select the newly created User assigned managed identity.
A page with details of the selected user assigned managed identity opens.
Click Access control (IAM).
The Access control (IAM) window opens.
Note
You require Owner access to add permissions to the registered application.
Click Add role assignments.
In the Add role assignments window, enter the following details:
Option
Definition
Role
Select a pre-defined role from the drop-down. The minimum required role is Reader. You can select Contributor or Owner as well.
Assign access to
Select User, group or service principal.
Select
Search and select the user based managed identity for which the role needs to be assigned.
Click Save.