Description |
This article describes how to reduce the Azure role permissions for a FortiGate-VM deployed in Microsoft Azure. It outlines the minimum required permissions to support basic FortiGate functionality, along with guidance for deployments that include high availability or SDN connectors. |
Scope | FortiGate-VM in Microsoft Azure environments/ |
Solution |
By default, FortiGate-VM may be assigned the Contributor role during deployment, which grants broad permissions across the resource group or subscription. This level of access can be excessive for a firewall appliance and may not align with the principle of least privilege.
The following example shows how to define a custom role in Azure with minimal required permissions for basic FortiGate-VM operation.
Minimal Required Permissions (Custom Role).
Replace/subscriptions/{your-subscription-id} with the appropriate subscription ID.
Additional Permissions (If Required). Additional permissions may be required depending on specific deployment features:
Related documents: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.