Adding privilege for provisioning of an Enterprise Application

%3CLINGO-SUB%20id%3D%22lingo-sub-3301566%22%20slang%3D%22en-US%22%3EAdding%20privilege%20for%20provisioning%20of%20an%20Enterprise%20Application%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3301566%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3ETo%20avoid%20the%20support%20task%20at%20our%20service%20desk%2C%20I%20would%20like%20to%20delegate%20the%20provisioning%20of%20one%20Enterprise%20Application%20which%20is%20used%20for%20SSO.%20Therefore%20I'm%20looking%20for%20the%20best%20practices%20for%20adding%20very%20limited%20privilege%20to%20one%20Azure%20AD%20user%20so%20that%20he%20can%20manage%20the%20group%20(add%2Fremove%20users)%20for%20the%20provisioning.%3C%2FP%3E%3CP%3EI%20will%20appreciate%20your%20recommandations.%3C%2FP%3E%3CP%3EThank%20you%3C%2FP%3E%3CP%3EPascal%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3301566%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Active%20Directory%20(AAD)%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EProvisioning%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3301648%22%20slang%3D%22en-US%22%3ERe%3A%20Adding%20privilege%20for%20provisioning%20of%20an%20Enterprise%20Application%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3301648%22%20slang%3D%22en-US%22%3EApplication%2Fservice%20principal%20management%20is%20one%20of%20the%20few%20areas%20where%20custom%20RBAC%20roles%20are%20supported%20in%20Azure%20AD%2C%20so%20you%20should%20be%20able%20to%20leverage%20those%3B%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Froles%2Fcustom-enterprise-apps%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Froles%2Fcustom-enterprise-apps%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3344696%22%20slang%3D%22en-US%22%3ERe%3A%20Adding%20privilege%20for%20provisioning%20of%20an%20Enterprise%20Application%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3344696%22%20slang%3D%22en-US%22%3EHello%20Vasil%2C%3CBR%20%2F%3EThanks%20to%20your%20information%2C%20I%20have%20created%20a%20custom%20role%2C%20assign%20it%20to%20a%20user%20and%20configure%20the%20access%20to%20a%20specific%20enterprise%20app%3CBR%20%2F%3EUnfortunately%20I%20observe%20that%20the%20user%20have%20access%20to%20other%20features%20as%20creating%20groups.%20I%20don't%20want%20that.%20My%20goal%20is%20to%20give%20a%20clear%20and%20limited%20access%20to%20a%20user%20(ideally%20I%20give%20him%20a%20link%20and%20he%20is%20directly%20in%20the%20context)%20so%20that%20he%20can%20just%20manage%20adding%2Fremoving%20users%20for%20provisining%20that%20app.%3CBR%20%2F%3EI%20will%20continue%20to%20search%20for%20a%20solution%20and%20appreciate%20your%20recommandations.%3CBR%20%2F%3EThank%20you%20very%20much%3CBR%20%2F%3EPascal%3C%2FLINGO-BODY%3E
New Contributor

Hello,

To avoid the support task at our service desk, I would like to delegate the provisioning of one Enterprise Application which is used for SSO. Therefore I'm looking for the best practices for adding very limited privilege to one Azure AD user so that he can manage the group (add/remove users) for the provisioning.

I will appreciate your recommandations.

Thank you

Pascal

 

2 Replies
Application/service principal management is one of the few areas where custom RBAC roles are supported in Azure AD, so you should be able to leverage those; https://docs.microsoft.com/en-us/azure/active-directory/roles/custom-enterprise-apps
Hello Vasil,
Thanks to your information, I have created a custom role, assign it to a user and configure the access to a specific enterprise app
Unfortunately I observe that the user have access to other features as creating groups. I don't want that. My goal is to give a clear and limited access to a user (ideally I give him a link and he is directly in the context) so that he can just manage adding/removing users for provisining that app.
I will continue to search for a solution and appreciate your recommandations.
Thank you very much
Pascal