{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-280-identify-who-can-maintain-a-managed-application-s-resource-group/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-280-identify-who-can-maintain-a-managed-application-s-resource-group/",
        "slug": "dse-20260909-280-identify-who-can-maintain-a-managed-application-s-resource-group",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-280-identify-who-can-maintain-a-managed-application-s-resource-group/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-280-identify-who-can-maintain-a-managed-application-s-resource-group.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-280-identify-who-can-maintain-a-managed-application-s-resource-group/"
        },
        "title": "Identify who can maintain a managed application's resource group",
        "summary": "An Azure Managed Application can restrict the customer, the publisher, neither, or both; the deployed permission model matters.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:27:16+00:00",
        "modified_at": "2026-09-10T01:23:49+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 247,
        "potentially_affected": "Azure Managed Applications and their managed resource groups in customer subscriptions.",
        "dse_recommendation": "Record the actual customer restriction and publisher access model before assigning maintenance or incident actions.",
        "primary_source": {
            "name": "Overview of Azure Managed Applications - Azure Managed Applications | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/overview",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>For Azure Managed Applications, publisher access and the customer&#8217;s deny assignment are optional. The default publisher-managed model grants publisher management access while restricting the customer through a deny assignment. A shared-access model instead gives both parties full access without that deny assignment.</p>\n<p>Locked mode gives the publisher no access while retaining the customer&#8217;s restriction. Customer-managed mode gives the customer full management access and removes publisher access. A publisher assignment can also be permanent or limited to a specified period. <a href=\"https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/overview\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the application definition, managed resource group and deployed permission choices. Do not infer operational access solely from the subscription owner or the supplier&#8217;s support role.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends a responsibility record that pairs each maintenance action with an identity that is actually authorized to perform it. Include the route for requesting time-limited publisher access where that is the chosen model. Ask who can investigate and remediate a resource problem under the existing restriction before promising a response procedure. Escalate an unworkable ownership arrangement through the agreed application-management process.</p>\n<h2>Verification</h2>\n<p>Inspect the current assignments and restrictions with an authorized reviewer. Test a permitted read or approved maintenance operation using the intended role, not an unrelated administrator. Record any time boundary on publisher access. If neither proposed operator can perform the required action, retain that as an unresolved responsibility gap rather than treating a successful application deployment as proof of maintainability.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/overview\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Overview of Azure Managed Applications</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nFor Azure Managed Applications, publisher access and the customer’s deny assignment are optional. The default publisher-managed model grants publisher management access while restricting the customer through a deny assignment. A shared-access model instead gives both parties full access without that deny assignment.\nLocked mode gives the publisher no access while retaining the customer’s restriction. Customer-managed mode gives the customer full management access and removes publisher access. A publisher assignment can also be permanent or limited to a specified period. Microsoft Learn.\nApplicability\nIdentify the application definition, managed resource group and deployed permission choices. Do not infer operational access solely from the subscription owner or the supplier’s support role.\nDSE recommendation\nDSE recommends a responsibility record that pairs each maintenance action with an identity that is actually authorized to perform it. Include the route for requesting time-limited publisher access where that is the chosen model. Ask who can investigate and remediate a resource problem under the existing restriction before promising a response procedure. Escalate an unworkable ownership arrangement through the agreed application-management process.\nVerification\nInspect the current assignments and restrictions with an authorized reviewer. Test a permitted read or approved maintenance operation using the intended role, not an unrelated administrator. Record any time boundary on publisher access. If neither proposed operator can perform the required action, retain that as an unresolved responsibility gap rather than treating a successful application deployment as proof of maintainability.\nOfficial references\nMicrosoft Learn: Overview of Azure Managed Applications. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nFor Azure Managed Applications, publisher access and the customer’s deny assignment are optional. The default publisher-managed model grants publisher management access while restricting the customer through a deny assignment. A shared-access model instead gives both parties full access without that deny assignment.\n\nLocked mode gives the publisher no access while retaining the customer’s restriction. Customer-managed mode gives the customer full management access and removes publisher access. A publisher assignment can also be permanent or limited to a specified period. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/overview).\n\n## Applicability\n\nIdentify the application definition, managed resource group and deployed permission choices. Do not infer operational access solely from the subscription owner or the supplier’s support role.\n\n## DSE recommendation\n\nDSE recommends a responsibility record that pairs each maintenance action with an identity that is actually authorized to perform it. Include the route for requesting time-limited publisher access where that is the chosen model. Ask who can investigate and remediate a resource problem under the existing restriction before promising a response procedure. Escalate an unworkable ownership arrangement through the agreed application-management process.\n\n## Verification\n\nInspect the current assignments and restrictions with an authorized reviewer. Test a permitted read or approved maintenance operation using the intended role, not an unrelated administrator. Record any time boundary on publisher access. If neither proposed operator can perform the required action, retain that as an unresolved responsibility gap rather than treating a successful application deployment as proof of maintainability.\n\n## Official references\n\n[Microsoft Learn: Overview of Azure Managed Applications](https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/overview). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-280-identify-who-can-maintain-a-managed-application-s-resource-group/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-280-identify-who-can-maintain-a-managed-application-s-resource-group/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-280-identify-who-can-maintain-a-managed-application-s-resource-group/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Identify who can maintain a managed application's resource group",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-280-identify-who-can-maintain-a-managed-application-s-resource-group/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-280-identify-who-can-maintain-a-managed-application-s-resource-group/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-280-identify-who-can-maintain-a-managed-application-s-resource-group/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-280-identify-who-can-maintain-a-managed-application-s-resource-group/",
                "headline": "Identify who can maintain a managed application's resource group",
                "description": "An Azure Managed Application can restrict the customer, the publisher, neither, or both; the deployed permission model matters.",
                "abstract": "An Azure Managed Application can restrict the customer, the publisher, neither, or both; the deployed permission model matters.",
                "articleBody": "Source facts\nFor Azure Managed Applications, publisher access and the customer’s deny assignment are optional. The default publisher-managed model grants publisher management access while restricting the customer through a deny assignment. A shared-access model instead gives both parties full access without that deny assignment.\nLocked mode gives the publisher no access while retaining the customer’s restriction. Customer-managed mode gives the customer full management access and removes publisher access. A publisher assignment can also be permanent or limited to a specified period. Microsoft Learn.\nApplicability\nIdentify the application definition, managed resource group and deployed permission choices. Do not infer operational access solely from the subscription owner or the supplier’s support role.\nDSE recommendation\nDSE recommends a responsibility record that pairs each maintenance action with an identity that is actually authorized to perform it. Include the route for requesting time-limited publisher access where that is the chosen model. Ask who can investigate and remediate a resource problem under the existing restriction before promising a response procedure. Escalate an unworkable ownership arrangement through the agreed application-management process.\nVerification\nInspect the current assignments and restrictions with an authorized reviewer. Test a permitted read or approved maintenance operation using the intended role, not an unrelated administrator. Record any time boundary on publisher access. If neither proposed operator can perform the required action, retain that as an unresolved responsibility gap rather than treating a successful application deployment as proof of maintainability.\nOfficial references\nMicrosoft Learn: Overview of Azure Managed Applications. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:27:16+00:00",
                "dateModified": "2026-09-10T01:23:49+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-280-identify-who-can-maintain-a-managed-application-s-resource-group/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-280-identify-who-can-maintain-a-managed-application-s-resource-group/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Identify who can maintain a managed application's resource group"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 247,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Overview of Azure Managed Applications - Azure Managed Applications | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/overview"
                }
            }
        ]
    }
}