如何通过Terraform获取Azure Security Insights应用的Object ID以配置角色
通过Terraform获取Azure Security Insights应用Object ID并分配角色
1. 查询Azure Security Insights服务主体
Azure Security Insights是微软托管的企业应用,其固定应用ID为cfa8b339-82a2-471a-a3c9-0fc0be7a4093,可以通过Terraform的azuread_service_principal数据源查询对应的服务主体Object ID:
data "azuread_service_principal" "security_insights" { application_id = "cfa8b339-82a2-471a-a3c9-0fc0be7a4093" }
2. 配置角色分配
将角色分配资源中的principal_id替换为数据源输出的Object ID,完成权限配置:
resource "azurerm_role_assignment" "sentinel_automation_contributor" { scope = "/subscriptions/<subId>/resourceGroups/<rg>" role_definition_name = "Azure Sentinel Automation Contributor" principal_id = data.azuread_service_principal.security_insights.object_id }
注意事项
- 该应用ID为微软全局固定值,所有Azure租户中均一致,无需担心变动
- 执行Terraform的账号需具备:读取Azure AD服务主体的权限,以及目标订阅/资源组的角色分配创建权限
内容的提问来源于stack exchange,提问作者dev007
相关产品推荐
相关产品推荐

