授予从整个订阅对容器的读取访问权限? [英] Grant Read access to a Container from an entire Subscription?

查看:101
本文介绍了授予从整个订阅对容器的读取访问权限?的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!

问题描述

你好

我了解可以允许对容器及其blob或blob进行匿名读取访问,或者为AD用户/组或托管服务身份授予角色.

I understand that it's possible to allow anonymous read access to a container and its blobs or just blobs OR grant a role to an AD user/group or Managed Service Identities.

我真正想做的是向整个订阅授予读取访问权限(或任何其他权限组合).这可能吗?

What I'd really like to do is grant read access (or any other permission combos) to an entire Subscription. Is this possible?

也许我是从错误的角度看的……任何想法都将不胜感激!

Perhaps I'm looking at this from the wrong angle... Any thoughts would be appreciated!

-Khalid

推荐答案

您必须创建一个自定义RBAC角色,然后查看它是否满足您的要求.参考: https://docs.microsoft.com/zh-CN/azure/role-based-access-control/tutorial-custom-role-powershell

You must create a custom RBAC role and see if that meets your requirement. Reference: https://docs.microsoft.com/en-us/azure/role-based-access-control/tutorial-custom-role-powershell

--------------------------------------------------- -------------------------------------------------- ----------------------------------
如果此答案有帮助,请单击"标记为答案",然后单击投票.要提供有关您的论坛体验的其他反馈,请单击 这里 

-----------------------------------------------------------------------------------------------------------------------------------
If this answer was helpful, click "Mark as Answer" and Up-Vote. To provide additional feedback on your forum experience, click here 


这篇关于授予从整个订阅对容器的读取访问权限?的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!

查看全文
登录 关闭
扫码关注1秒登录
发送“验证码”获取 | 15天全站免登陆