How Shared Image Gallery can be used for sharing accross tenants and subcriptions

%3CLINGO-SUB%20id%3D%22lingo-sub-2013638%22%20slang%3D%22en-US%22%3EHow%20Shared%20Image%20Gallery%20can%20be%20used%20for%20sharing%20accross%20tenants%20and%20subcriptions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2013638%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3EI%20used%20RBAC%20share%20feature%20as%20noted%20in%20documentation%20but%20it%20does%20not%20seem%20to%20work%20as%20expected.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3EI%20have%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3EAzure%20AD%201%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3Band%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3ESubcription%201%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3Bwhere%20shared%20image%20gallery%20is%20being%20hosted.%20I%20also%20have%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3EAzure%20AD%202%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3Band%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3ESubscription%202%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3Bwhere%20I'd%20like%20to%20create%20VM%20from%20shared%20image%20gallery%20version.%20I%20gave%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3Euser%201%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3Bin%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3EAzure%20AD%202%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3Breader%20permission%20to%20%3CSTRONG%3EShared%20Image%20gallery%3C%2FSTRONG%3E%20which%20works%20fine%20and%20that%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3Euser%201%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3Bcan%20see%20all%20images%20in%20shared%20image%20gallery.%20Question%20is%20how%20do%20I%20create%20VM%20from%20image%20since%20the%20only%20option%26nbsp%3B%3C%2FSPAN%3Euser%201%3CSPAN%3E%26nbsp%3Bsees%20in%20subscription%20is%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3ESubscription%201%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3Bsince%20it's%20logged%20to%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3EAzure%20AD%201%3C%2FSTRONG%3E%3CSPAN%3E.%20How%20do%20I%20deploy%20that%20image%20to%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3ESubscription%202%3C%2FSTRONG%3E%20which%20is%20under%20%3CSTRONG%3EAzure%20AD%202%3C%2FSTRONG%3E%3CSPAN%3E%3F%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2013638%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECompute%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2028059%22%20slang%3D%22en-US%22%3ERe%3A%20How%20Shared%20Image%20Gallery%20can%20be%20used%20for%20sharing%20accross%20tenants%20and%20subcriptions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2028059%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F66962%22%20target%3D%22_blank%22%3E%40Gregory%20Suvalian%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20user%20who%20is%20outside%20the%20organization%20need%20to%20accept%20the%20invitation%20%3A%20Have%20you%20done%20that%20in%20the%20role%20assignment%20process%3F%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUser%20can%20see%20both%20subscriptions%20but%20he%20will%20need%20to%20be%20invited%20in%20AD2%20to%20be%20able%20to%20manage%20resources%20in%26nbsp%3B%20Subscription%202.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

I used RBAC share feature as noted in documentation but it does not seem to work as expected.

I have Azure AD 1 and Subcription 1 where shared image gallery is being hosted. I also have Azure AD 2 and Subscription 2 where I'd like to create VM from shared image gallery version. I gave user 1 in Azure AD 2 reader permission to Shared Image gallery which works fine and that user 1 can see all images in shared image gallery. Question is how do I create VM from image since the only option user 1 sees in subscription is Subscription 1 since it's logged to Azure AD 1. How do I deploy that image to Subscription 2 which is under Azure AD 2?

1 Reply

@Gregory Suvalian 

 

Hi

 

The user who is outside the organization need to accept the invitation : Have you done that in the role assignment process?  

 

User can see both subscriptions but he will need to be invited in AD2 to be able to manage resources in  Subscription 2.