# Grant service-catalog definition access separately from managed-resource administration

> Which permission lets intended consumers read a managed-application definition without confusing it with publisher administration?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-126-grant-service-catalog-definition-access-separately-from-managed-resource/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:29:50+00:00
- Modified: 2026-09-10T00:52:38+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Which permission lets intended consumers read a managed-application definition without confusing it with publisher administration?

## Potentially affected

Organizations publishing Azure Managed Applications through the service catalog.

## DSE recommendation

DSE recommends checking catalog-definition read access using the intended consumer identity before changing publisher authorizations.

## Article

## Source facts

Microsoft directs publishers to give intended users at least Reader access to a service-catalog managed-application definition, noting that subscription or resource-group inheritance may already provide it. The definition’s authorization configuration serves a different purpose: it identifies the principal and role used for permissions on the managed resource group. Reading the catalog definition and administering deployed resources are separate access checks. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/publish-service-catalog-app).

## Applicability

Use this distinction when a published definition is available to its creator but not to an intended consumer. Keep the investigation focused on that definition and the consumer’s effective read access. Do not treat a successful publisher session as evidence that another user can read it.

## DSE recommendation

DSE recommends checking catalog-definition read access using the intended consumer identity before changing publisher authorizations. Inspect inherited access first, then propose the narrowest appropriate assignment if a genuine gap remains. Record catalog access and managed-resource administration as separate decisions. Do not add the consumer to a privileged publisher group simply to address definition visibility, or assume that Reader access proves every permission needed for a later deployment.

## Verification

Use an authorized representative account to open the exact definition and confirm that its expected contents are available. Record the identity, definition ID and access path that produced that result. Review the managed-resource authorization entries independently against the approved maintainer list. Close the visibility issue only after testing the consumer’s experience, while preserving a separate review for deployment and ongoing resource-management permissions.

## Official references

[Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/publish-service-catalog-app). Source retrieved September 9, 2026.

## Primary reference

- Name: Create and publish Azure Managed Application in service catalog - Azure Managed Applications | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/publish-service-catalog-app
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Grant service-catalog definition access separately from managed-resource administration,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-126-grant-service-catalog-definition-access-separately-from-managed-resource/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
