Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

With auto_create no interactive user is the owner of the Workspace Enterprise App #2625

Closed
marrobi opened this issue Sep 21, 2022 · 0 comments · Fixed by #2627
Closed

With auto_create no interactive user is the owner of the Workspace Enterprise App #2625

marrobi opened this issue Sep 21, 2022 · 0 comments · Fixed by #2627
Assignees
Labels
bug Something isn't working

Comments

@marrobi
Copy link
Member

marrobi commented Sep 21, 2022

When creating a workspace with auto_create the workspace owner is set to the Application Admin account. This means that to add any users to the App Roles the interactive user must have privileges to access all Enterprise Apps in Azure AD, or ask their AD Admin to grant them access.

I suggest the creator of the workspace is also made an owner of the Workspace Enterprise application. This will mean they can also view sign in logs.

The user needs adding here: https://github.com/marrobi/AzureTRE/blob/caf6a9c2e68f7e74684249d112e2b083f77ac3a9/templates/workspaces/base/terraform/aad/aad.tf#L97

@marrobi marrobi added the bug Something isn't working label Sep 21, 2022
@marrobi marrobi added this to the Release 0.5 milestone Sep 21, 2022
@marrobi marrobi self-assigned this Sep 21, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant