Sep 01 2021 07:49 AM
We provide resource groups for each project and bundle them together in a subscription. The project developer only have rights on their corresponding resource group, no rights on subscription level and/or resource groups in the same subscription which not belong to their projects.
now we have the problem, that these developer can't see the secure score for their resource group. only when we give them "security reader" permission on subscription level they can see the secure score, but they also can see all other resources/resource groups to which they don't need access.
so this is kind of a feature request to view the secure score for whom someone has access to in a subscription, but don't give them any permission on resources they don't need access to in the same subscription.
Sep 02 2021 11:03 AM
SolutionTwo things here.
ASC currently does not have an option to track/show SS at the resource group level, only for a subscription or management group. We hear this ask pretty often and it's in our backlog with no concrete ETA yet.
If you want to give someone ability to track SS, you may consider using on of the built-in ASC workbooks or PowerBI report. In both cases you will only need to give away the Reader access for a workspace used to store the exported data.