enable the "Support Request Contributor" role to be scope at the resource group level for opening premier tickets.
Currently we are operating in a shared subscription model where each app team is assigned specific resource group(s) and their access is scoped at this level. For them to open premier tickets from ARM, they have to be added as Support Request Contributor at the subscription level.
This enables visibility to all resource groups in the subscription and impacts the experience of the user. The complaints I have received are "Now I have to search for my resource group" and "I thought we had our own subscription"
The concept of resource groups is great but loses value when users have to be added to the subscription level
I agree, we have a shared subscription and only want to allow users to submit premier tickets for their own resources.
Brandur Kragesteen Holm Petersen commented
It's just dumb that they give you the "illusion" that this is already possible and when you try and set it up, it of course doesn't work. Then you create a support ticket about the issue (wonder how many other people have done the same) and get told that you have to create it on the Subscription level (which means the user can view all of your Resource Groups [very annoying and can be confusing for some as well]).
Please just make it work as one might expect it to work already (but doesn't) :)
Kim Suarez commented
This violates every principle of RBAC
Sebastian Lilienthal commented
Please solve this. Having to add Support Request Contributor Role on a Subscription Level is a real Pain. I am forced to share all the Resource Group Information with external Partners that support us just on one Resource Group.
Geert Cools commented
Will this behavior be changed in the future?
Or is it possible to work around the need to give the users access on the subscription level?