GuideInformationCybersecurityIT

Grant service-catalog definition access separately from managed-resource administration

Which permission lets intended consumers read a managed-application definition without confusing it with publisher administration?

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defenseGuide · 2 min read
Executive summary

What you need to know

Which permission lets intended consumers read a managed-application definition without confusing it with publisher administration?

Potentially affected

Organizations publishing Azure Managed Applications through the service catalog.

DSE recommendation

DSE recommends checking catalog-definition read access using the intended consumer identity before changing publisher authorizations.

Source facts

Microsoft directs publishers to give intended users at least Reader access to a service-catalog managed-application definition, noting that subscription or resource-group inheritance may already provide it. The definition’s authorization configuration serves a different purpose: it identifies the principal and role used for permissions on the managed resource group. Reading the catalog definition and administering deployed resources are separate access checks. Microsoft Learn.

Applicability

Use this distinction when a published definition is available to its creator but not to an intended consumer. Keep the investigation focused on that definition and the consumer’s effective read access. Do not treat a successful publisher session as evidence that another user can read it.

DSE recommendation

DSE recommends checking catalog-definition read access using the intended consumer identity before changing publisher authorizations. Inspect inherited access first, then propose the narrowest appropriate assignment if a genuine gap remains. Record catalog access and managed-resource administration as separate decisions. Do not add the consumer to a privileged publisher group simply to address definition visibility, or assume that Reader access proves every permission needed for a later deployment.

Verification

Use an authorized representative account to open the exact definition and confirm that its expected contents are available. Record the identity, definition ID and access path that produced that result. Review the managed-resource authorization entries independently against the approved maintainer list. Close the visibility issue only after testing the consumer’s experience, while preserving a separate review for deployment and ongoing resource-management permissions.

Official references

Microsoft Learn. Source retrieved September 9, 2026.

Primary reference

Review the official source

Create and publish Azure Managed Application in service catalog - Azure Managed Applications | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE