Azure-docs: Why does deployment to customer tenant have to be done with a member of the customer tenant? How about AOBO?

Created on 15 Apr 2020  Â·  4Comments  Â·  Source: MicrosoftDocs/azure-docs

https://docs.microsoft.com/en-us/azure/lighthouse/how-to/onboard-customer#deploy-the-azure-resource-manager-templates

image

So far when testing this out, we've been using AOBO from our CSP Partner tenant to a customer tenant, and it seems to work.

  • Why does documentation say that it has to be done by a member of the customer tenant?
  • What limitations do I have with a AOBO admin in this regard, it will be owner on the subscription, isn't that enough?
  • A B2B user with Global Admin (Azure AD) and Owner (Subscription) will not work either? Why?

Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Pri2 assigned-to-author lighthoussvc product-question triaged

All 4 comments

@o-l-a-v, thank you for reaching out. We are looking into this and would get back to you soon on this thread.

@o-l-a-v As per document, user of the customer tenant can deploy ARM template. As per my understanding user can be AOBO or any user who has Owner role.
image

@JnHs Can you please provide your insights on the same?

Hi @o-l-a-v - sorry for the delayed response. Yes, any user with AOBO access can onboard a subscription. This is mentioned on our CSP topic https://docs.microsoft.com/en-us/azure/lighthouse/concepts/cloud-solution-provider#azure-delegated-resource-management but I'll clarify this in the onboarding topic as well.

I've added this info to the topic, will close this now - please let us know if you have further questions! #please-close

Was this page helpful?
0 / 5 - 0 ratings

Related issues

Ponant picture Ponant  Â·  3Comments

spottedmahn picture spottedmahn  Â·  3Comments

DeepPuddles picture DeepPuddles  Â·  3Comments

JamesDLD picture JamesDLD  Â·  3Comments

Agazoth picture Agazoth  Â·  3Comments