Azure-docs: Clarification on groups and role assignments

Created on 2 Jun 2020  Â·  4Comments  Â·  Source: MicrosoftDocs/azure-docs

Hi, couple of comments on the Steps 1 and 2 of Access Control for Workspace:

In step 1, it indicates
Add Synapse_WORKSPACENAME_Admins to ProjectSynapse_WORKSPACENAME_Users
which I think is a typo and should be:
Add Synapse_WORKSPACENAME_Admins to Synapse_WORKSPACENAME_Users

Moreover, some explanation on this should be provided, such as group membership, permission inheritance and how to perform this tasks, maybe with links to the docs in additional comments.
This is important also because there are known limitations on groups membership, e.g. the Synapse_WORKSPACENAME_Users group could not be an on-premises AD Group, since that is not supported.

In the Step 2, it indicates which roles to assign to the different groups created on step 1, but step d) makes no sense, since there is no entity called WORKSPACENAME defined in step 1 or mentioned before that.

Finally, in the next steps links, _see Synapse SQL access control_ links to the same page.


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

/subsvc Pri2 assigned-to-author doc-bug synapse-analyticsvc triaged

Most helpful comment

Thank you both! I'll close this out since the fix has been deployed.

All 4 comments

Hi @jdocampo

You are correct, there is a typo for step 1.
Thank you for raising this! I just added more informations related to the AAD groups in notes.

Related to

In the Step 2, it indicates which roles to assign to the different groups created on step 1, but step d) makes no sense, since there is no entity called WORKSPACENAME defined in step 1 or mentioned before that.

WORKSPACENAME is a placeholder for the actual workspace name, role in this case is Storage Blob Data Contributor.

Changes will be visible soon in the documentation when reviewers approve the change.

Hi @azaricstefan
First thanks for the quick response :)

So WORKSPACENAME relates to the Managed Identity created for the workspace?
That will make senses, although I thought that role assignment was automatically done on the workspace provisioning for the default storage.

If that's the case, maybe a prior mention to the managed identity will help to clarify things.

Again, many thanks!

Name of the Managed Identity is same as name of the workspace.

Managed identity is assigned Storage Blob Data Contributor role only if you choose storage account from the dropdown menu, if you added manual config to the storage during provisioning of the workspace then you should assign permissions to the Managed Identity manually.

Thank you both! I'll close this out since the fix has been deployed.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

varma31 picture varma31  Â·  3Comments

bdcoder2 picture bdcoder2  Â·  3Comments

jamesgallagher-ie picture jamesgallagher-ie  Â·  3Comments

jharbieh picture jharbieh  Â·  3Comments

behnam89 picture behnam89  Â·  3Comments