Do Azure DevOps Service Connection need elevated permissions?

Viewed 142

I'm using Azure DevOps services to create service connection but getting errors. I am trying to follow the steps outlined here

These are the steps I followed:

  • Add a new AAD app registration with secret.

  • In DevOps, from project settings create a new service connection.

    • Connection type: ARM
    • Authentication method: Serviceprincipal (manual)
    • Env: Azure Cloud
    • Scope: Subscription
    • Subscription Id: xxx
    • Subscription name: xxx
    • service principal id: xxx
    • service principal key: xxx
    • Tenant Id: xxx

When I click Verify, I get this error:

Failed to query service connection API: 'https://management.azure.com/subscriptions/xxx?api-version=2016-06-01'. Status Code: 'Forbidden', Response from server: '{"error":{"code":"AuthorizationFailed","message":"The client 'abc' with object id 'abc' does not have authorization to perform action 'Microsoft.Resources/subscriptions/read' over scope '/subscriptions/xxx' or the scope is invalid. If access was recently granted, please refresh your credentials."}}'

So,

Does this mean, my app registration need to have read permission on this xxx subscription? Can't I scope it to resource group level? If yes, how can I do that as I don't see that option in portal? Thanks!

2 Answers

I tried to reproduce the same in my environment and got the same error as below:

enter image description here

Does this mean, my app registration needs to have read permission on this xxx subscription? Can't I scope it to resource group level?

Yes, your app registration needs to have read permission on that subscription level. You cannot scope it to resource group level as the query https://management.azure.com/subscriptions/xxx?api-version=2016-06-01 is related to subscriptions.

Read permission will be included in roles like reader, contributor and owner. For least privilege, I assigned reader role to the app like below:

Go to Azure Portal -> Subscriptions -> Your Subscription -> Access Control(IAM) -> Add role assignment -> Select Role

enter image description here

After assigning that role, verification is successful like below:

enter image description here

When you create ARM service principle (Manual) type Service Connection, you need to manually add role assignment for this service principle inside your Azure Subscription in Azure Portal.

In common, you will need to give this service principle “Contribute” role to perform the action.

Find the Overview Page of this app registration in AAD.

enter image description here

In your Azure Subscription page, click IAM -> Add -> Add role assignment

enter image description here

Select the name of this app and assign it a "Contribute" role of this Azure Subscription.

enter image description here

Related