Skip to content

Conversation

@FlorentATo
Copy link

@FlorentATo FlorentATo commented Jun 9, 2025

This suggestion expends the list of exception to include user-scoped roles for reading individual private SSH key from Bastion UI.

This scenario allows cloud administrators to use of a single Key Vault instance to centrally manage users' private SSH keys, while restricting access to individual keys to said users using Azure RBAC.

This is useful in situations where letting users have a local copy of their private key isn't desired (e.g. for users with decentralized access).

image

URL: https://learn.microsoft.com/en-us/azure/key-vault/general/rbac-guide?tabs=azure-cli

@prmerger-automator
Copy link
Contributor

@FlorentATo : Thanks for your contribution! The author(s) and reviewer(s) have been notified to review your proposed change.

@learn-build-service-prod
Copy link
Contributor

Learn Build status updates of commit 5d6880a:

✅ Validation status: passed

File Status Preview URL Details
articles/key-vault/general/rbac-guide.md ✅Succeeded

For more details, please refer to the build report.

@v-regandowner
Copy link
Contributor

@msmbaldwin - Can you review the proposed changes?

IMPORTANT: When the changes are ready for publication, adding a #sign-off comment is the best way to signal that the PR is ready for the review team to merge.

#label:"aq-pr-triaged"
@MicrosoftDocs/public-repo-pr-review-team

@learn-build-service-prod
Copy link
Contributor

Learn Build status updates of commit a4e0ae5:

✅ Validation status: passed

File Status Preview URL Details
articles/key-vault/general/rbac-guide.md ✅Succeeded

For more details, please refer to the build report.

@learn-build-service-prod
Copy link
Contributor

Learn Build status updates of commit f742998:

✅ Validation status: passed

File Status Preview URL Details
articles/key-vault/general/rbac-guide.md ✅Succeeded

For more details, please refer to the build report.

@github-actions
Copy link

This pull request has been inactive for at least 14 days. If you are finished with your changes, don't forget to sign off. See the contributor guide for instructions.
Get Help
Docs Support Teams Channel
Resolve Merge Conflict

@v-dirichards
Copy link
Contributor

@msmbaldwin Could you review this proposed update to your article and enter #sign-off in a comment if it's ready to merge?

Thanks!

@github-actions github-actions bot removed the inactive label Jul 11, 2025
@v-dirichards
Copy link
Contributor

@msmbaldwin

Can you review this old PR and determine whether it needs to be closed or merged?

@MicrosoftDocs/public-repo-pr-review-team

@github-actions
Copy link

github-actions bot commented Aug 5, 2025

This pull request has been inactive for at least 14 days. If you are finished with your changes, don't forget to sign off. See the contributor guide for instructions.
Get Help
Docs Support Teams Channel
Resolve Merge Conflict

@FlorentATo
Copy link
Author

FlorentATo commented Aug 15, 2025

Any chance you could review this quick PR @msmbaldwin ?

@github-actions github-actions bot removed the inactive label Aug 15, 2025
@github-actions
Copy link

This pull request has been inactive for at least 14 days. If you are finished with your changes, don't forget to sign off. See the contributor guide for instructions.
Get Help
Docs Support Teams Channel
Resolve Merge Conflict

@FlorentATo
Copy link
Author

Bump @msmbaldwin @v-dirichards ?

@github-actions github-actions bot removed the inactive label Sep 17, 2025
@v-ccolin
Copy link
Contributor

I sent an email to the content owner today.

@MicrosoftDocs/public-repo-pr-review-team

Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates the Azure Key Vault RBAC best practices documentation to include additional guidance for SSH private key access scenarios. It expands the exceptions for assigning roles at individual resource levels to accommodate user-scoped access patterns.

  • Adds SSH private key access via Azure Bastion as a valid exception to the general best practice
  • Restructures the exceptions list for better readability and completeness
  • Minor formatting cleanup in code examples (removing unnecessary line breaks in JSON arrays)

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

@learn-build-service-prod
Copy link
Contributor

Learn Build status updates of commit c6415e5:

✅ Validation status: passed

File Status Preview URL Details
articles/key-vault/general/rbac-guide.md ✅Succeeded

For more details, please refer to the build report.

@v-dirichards
Copy link
Contributor

@msmbaldwin

Can you review this old PR and determine whether it needs to be closed or merged?

@MicrosoftDocs/public-repo-pr-review-team

@github-actions
Copy link

This pull request has been inactive for at least 14 days. If you are finished with your changes, don't forget to sign off. See the contributor guide for instructions.
Get Help
Docs Support Teams Channel
Resolve Merge Conflict

@v-ccolin
Copy link
Contributor

I sent an email to the content owner today.

@MicrosoftDocs/public-repo-pr-review-team

@github-actions github-actions bot removed the inactive label Oct 20, 2025
@github-actions
Copy link

github-actions bot commented Nov 3, 2025

This pull request has been inactive for at least 14 days. If you are finished with your changes, don't forget to sign off. See the contributor guide for instructions.
Get Help
Docs Support Teams Channel
Resolve Merge Conflict

@FlorentATo
Copy link
Author

Bump @v-ccolin @v-dirichards ? 🙃

@github-actions github-actions bot removed the inactive label Nov 4, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants