Applies to: Nerdio Manager for MSP (NMM)
Version : 0.7.0 and greater
Disclaimer : Nerdio Manager for MSP is an automation and management solution. NMM Partners are responsible for understanding, and managing Microsoft Identity Services, M365 and Azure Resources. For Identity and Azure support, please contact your Distributor or Microsoft directly.
- Guest User access to Customer Tenant
- Reader Permission to Customer Subscription
- Accessing Customer Directory and Subscription in Azure Portal
Step 1 - Invite yourself to the Customers AAD Tenant via GUEST Access
In this step we will focus on getting access to the clients Tenant via Guest User Access in AAD
- In the Azure Portal, open Azure Active Directory (AAD) and browse to the Users section on the left blade.
- Click, New Guest User
- Fill out the necessary information and make sure you ACCEPT the Guest invitation once received.
Note - Examples Below
Guest User in Azure AD
Step 2 - Assign READER permission on the Customer Subscription
In this step we will focus on granting permission to the customers subscription
- Log in to the Microsoft Azure portal.
In the left-hand menu, click All Services.
- In the General section, click Subscriptions.
- In the subscription table, click the applicable subscription.
The Overview page for the subscription appears.
- In the menu for the subscription, click Access control (IAM).
The Access control (IAM) page appears.
- Click the +Add button.
A pop-up menu appears.
- Click Add role assignment.
- In the Add role assignment plane, in the Role drop-down, select Reader.
- In the Select field, search for the "Guest" User Object from Step1
- Click the Save button.
Step 3 - Switching to the Customer Directory in Azure
In this step we will focus on gaining access to the new Directory and Subscription, via the Azure Portal
When you go to view Monitoring you may not be able to see the Customer Subscription and Resources within your current Directory. You will need to change Directories via Azure Portal to gain access.
If you see...
- From the Azure portal click the current signed in username at the top right of the screen
- Then Click "Switch Directory"
- Select the Customer Directory
- You should now be able to see the Subscription and Resources
- Remember to switch back if you're unable to see resources in other accounts after managing this Customer Directory