Add roles/permissions to section: Add Update Compliance to your Azure subscription

adding the following information on roles required to enable, write or read in log analytics.
This commit is contained in:
ricastil
2022-03-10 11:56:19 -06:00
committed by GitHub
parent eb8af2d742
commit 0fa76610da

View File

@ -51,8 +51,9 @@ Before you begin the process to add Update Compliance to your Azure subscription
## Add Update Compliance to your Azure subscription
Update Compliance is offered as an Azure Marketplace application which is linked to a new or existing [Azure Log Analytics](/azure/log-analytics/query-language/get-started-analytics-portal) workspace within your Azure subscription. To configure this, follow these steps:
Update Compliance is offered as an Azure Marketplace application which is linked to a new or existing [Azure Log Analytics](/azure/log-analytics/query-language/get-started-analytics-portal) workspace within your Azure subscription. Please note that for the following steps you must have one of the following [Azure roles](https://docs.microsoft.com/en-us/azure/role-based-access-control/rbac-and-directory-admin-roles#azure-roles) at minimum in order to add the solution: Owner or Contributor.
To configure this, follow these steps:
1. Go to the [Update Compliance page in the Azure Marketplace](https://azuremarketplace.microsoft.com/marketplace/apps/Microsoft.WaaSUpdateInsights?tab=Overview). You might need to login to your Azure subscription to access this.
2. Select **Get it now**.
3. Choose an existing or configure a new Log Analytics Workspace, ensuring it is in a **Compatible Log Analytics region** from the following table. Although an Azure subscription is required, you won't be charged for ingestion of Update Compliance data.
@ -60,6 +61,11 @@ Update Compliance is offered as an Azure Marketplace application which is linked
- [Azure Update Management](/azure/automation/automation-intro#update-management) users should use the same workspace for Update Compliance.
4. After your workspace is configured and selected, select **Create**. You'll receive a notification when the solution has been successfully created.
Once the solution is in place, a user can leverage one of the following Azure roles with Update Compliance:
• To edit and write queries we recommend the [Log Analytics Contributor ](https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#log-analytics-contributor)
• To read and only view date we recommend the [Log Analytics Reader](https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#log-analytics-reader)
|Compatible Log Analytics regions |
| ------------------------------- |
|Australia Central |