Technical Tip: Azure Role Requirements for FortiGate-VM
| Description | This article describes how to reduce the Azure role permissions for a FortiGate-VM deployed in Microsoft Azure. It outlines the minimum required permissions to support basic FortiGate functionality, along with guidance for deployments that include high availability or SDN connectors. |
| Scope | FortiGate-VM in Microsoft Azure environments/ |
| Solution | By default, FortiGate-VM may be assigned the Contributor role during deployment, which grants broad permissions across the resource group or subscription. This level of access can be excessive for a firewall appliance and may not align with the principle of least privilege.
The following example shows how to define a custom role in Azure with minimal required permissions for basic FortiGate-VM operation.
Minimal Required Permissions (Custom Role).
Replace/subscriptions/{your-subscription-id} with the appropriate subscription ID.
Additional Permissions (If Required). Additional permissions may be required depending on specific deployment features:
Related documents: |
