{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-084-include-image-and-publisher-tenant-identifiers-in-an-rbac-gallery-handoff/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-084-include-image-and-publisher-tenant-identifiers-in-an-rbac-gallery-handoff/",
        "slug": "dse-20260909-084-include-image-and-publisher-tenant-identifiers-in-an-rbac-gallery-handoff",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-084-include-image-and-publisher-tenant-identifiers-in-an-rbac-gallery-handoff/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-084-include-image-and-publisher-tenant-identifiers-in-an-rbac-gallery-handoff.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-084-include-image-and-publisher-tenant-identifiers-in-an-rbac-gallery-handoff/"
        },
        "title": "Include image and publisher-tenant identifiers in an RBAC gallery handoff",
        "summary": "Why can a recipient have gallery access yet still lack the information needed to deploy an image?",
        "format": {
            "slug": "checklist",
            "name": "Checklist"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:30:32+00:00",
        "modified_at": "2026-09-10T00:35:08+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 241,
        "potentially_affected": "Publishers sharing Azure Compute Gallery resources with named recipients through Azure RBAC, especially across tenants.",
        "dse_recommendation": "Deliver the intended image resource ID and publisher tenant ID alongside the approved access scope.",
        "primary_source": {
            "name": "Share Resources in Azure Compute Gallery - Azure Virtual Machines | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/share-gallery",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Azure Compute Gallery RBAC recipients need the supplied imageID to deploy a VM or scale set; Microsoft says they cannot list images shared through that method. A recipient outside the publisher&#8217;s tenant also needs its tenantID for access verification and cannot independently query that value. Gallery-level sharing includes definitions and versions, whereas definition-level sharing does not expose the gallery itself. <a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/share-gallery\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Apply this handoff to named users, groups, or service principals receiving RBAC access. Identify both the publishing tenant and the tenant where deployment is intended. Do not mistake a missing discovery experience for proof that the role assignment failed or that a wider sharing mode is required.</p>\n<h2>DSE recommendation</h2>\n<p>Deliver the intended image resource ID and publisher tenant ID alongside the approved access scope. Have the publisher and recipient confirm the target image version and account context together. Record who owns updating that handoff when the image changes. Review the granted scope deliberately rather than broadening access merely to make a catalog appear.</p>\n<h2>Verification</h2>\n<p>Using an authorized recipient account, follow the cross-tenant sign-in and image-consumption procedure with the supplied identifiers. Compare a failed attempt&#8217;s tenant and resource IDs with the approved record before changing permissions. Demonstrate deployment from the intended version in a bounded test and retain the resulting provenance. Keep publisher access, recipient identity, and destination deployment rights distinguishable when documenting the outcome.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/share-gallery\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Share gallery resources using RBAC</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nAzure Compute Gallery RBAC recipients need the supplied imageID to deploy a VM or scale set; Microsoft says they cannot list images shared through that method. A recipient outside the publisher’s tenant also needs its tenantID for access verification and cannot independently query that value. Gallery-level sharing includes definitions and versions, whereas definition-level sharing does not expose the gallery itself. Microsoft Learn.\nApplicability\nApply this handoff to named users, groups, or service principals receiving RBAC access. Identify both the publishing tenant and the tenant where deployment is intended. Do not mistake a missing discovery experience for proof that the role assignment failed or that a wider sharing mode is required.\nDSE recommendation\nDeliver the intended image resource ID and publisher tenant ID alongside the approved access scope. Have the publisher and recipient confirm the target image version and account context together. Record who owns updating that handoff when the image changes. Review the granted scope deliberately rather than broadening access merely to make a catalog appear.\nVerification\nUsing an authorized recipient account, follow the cross-tenant sign-in and image-consumption procedure with the supplied identifiers. Compare a failed attempt’s tenant and resource IDs with the approved record before changing permissions. Demonstrate deployment from the intended version in a bounded test and retain the resulting provenance. Keep publisher access, recipient identity, and destination deployment rights distinguishable when documenting the outcome.\nOfficial references\nMicrosoft Learn: Share gallery resources using RBAC. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nAzure Compute Gallery RBAC recipients need the supplied imageID to deploy a VM or scale set; Microsoft says they cannot list images shared through that method. A recipient outside the publisher’s tenant also needs its tenantID for access verification and cannot independently query that value. Gallery-level sharing includes definitions and versions, whereas definition-level sharing does not expose the gallery itself. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/share-gallery).\n\n## Applicability\n\nApply this handoff to named users, groups, or service principals receiving RBAC access. Identify both the publishing tenant and the tenant where deployment is intended. Do not mistake a missing discovery experience for proof that the role assignment failed or that a wider sharing mode is required.\n\n## DSE recommendation\n\nDeliver the intended image resource ID and publisher tenant ID alongside the approved access scope. Have the publisher and recipient confirm the target image version and account context together. Record who owns updating that handoff when the image changes. Review the granted scope deliberately rather than broadening access merely to make a catalog appear.\n\n## Verification\n\nUsing an authorized recipient account, follow the cross-tenant sign-in and image-consumption procedure with the supplied identifiers. Compare a failed attempt’s tenant and resource IDs with the approved record before changing permissions. Demonstrate deployment from the intended version in a bounded test and retain the resulting provenance. Keep publisher access, recipient identity, and destination deployment rights distinguishable when documenting the outcome.\n\n## Official references\n\n[Microsoft Learn: Share gallery resources using RBAC](https://learn.microsoft.com/en-us/azure/virtual-machines/share-gallery). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-084-include-image-and-publisher-tenant-identifiers-in-an-rbac-gallery-handoff/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-084-include-image-and-publisher-tenant-identifiers-in-an-rbac-gallery-handoff/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-084-include-image-and-publisher-tenant-identifiers-in-an-rbac-gallery-handoff/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Include image and publisher-tenant identifiers in an RBAC gallery handoff",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-084-include-image-and-publisher-tenant-identifiers-in-an-rbac-gallery-handoff/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-084-include-image-and-publisher-tenant-identifiers-in-an-rbac-gallery-handoff/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-084-include-image-and-publisher-tenant-identifiers-in-an-rbac-gallery-handoff/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-084-include-image-and-publisher-tenant-identifiers-in-an-rbac-gallery-handoff/",
                "headline": "Include image and publisher-tenant identifiers in an RBAC gallery handoff",
                "description": "Why can a recipient have gallery access yet still lack the information needed to deploy an image?",
                "abstract": "Why can a recipient have gallery access yet still lack the information needed to deploy an image?",
                "articleBody": "Source facts\nAzure Compute Gallery RBAC recipients need the supplied imageID to deploy a VM or scale set; Microsoft says they cannot list images shared through that method. A recipient outside the publisher’s tenant also needs its tenantID for access verification and cannot independently query that value. Gallery-level sharing includes definitions and versions, whereas definition-level sharing does not expose the gallery itself. Microsoft Learn.\nApplicability\nApply this handoff to named users, groups, or service principals receiving RBAC access. Identify both the publishing tenant and the tenant where deployment is intended. Do not mistake a missing discovery experience for proof that the role assignment failed or that a wider sharing mode is required.\nDSE recommendation\nDeliver the intended image resource ID and publisher tenant ID alongside the approved access scope. Have the publisher and recipient confirm the target image version and account context together. Record who owns updating that handoff when the image changes. Review the granted scope deliberately rather than broadening access merely to make a catalog appear.\nVerification\nUsing an authorized recipient account, follow the cross-tenant sign-in and image-consumption procedure with the supplied identifiers. Compare a failed attempt’s tenant and resource IDs with the approved record before changing permissions. Demonstrate deployment from the intended version in a bounded test and retain the resulting provenance. Keep publisher access, recipient identity, and destination deployment rights distinguishable when documenting the outcome.\nOfficial references\nMicrosoft Learn: Share gallery resources using RBAC. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:30:32+00:00",
                "dateModified": "2026-09-10T00:35:08+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-084-include-image-and-publisher-tenant-identifiers-in-an-rbac-gallery-handoff/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-084-include-image-and-publisher-tenant-identifiers-in-an-rbac-gallery-handoff/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Include image and publisher-tenant identifiers in an RBAC gallery handoff"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Checklist",
                    "Information priority"
                ],
                "genre": "Checklist",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 241,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Share Resources in Azure Compute Gallery - Azure Virtual Machines | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/share-gallery"
                }
            }
        ]
    }
}