# Identify who can maintain a managed application's resource group

> An Azure Managed Application can restrict the customer, the publisher, neither, or both; the deployed permission model matters.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-280-identify-who-can-maintain-a-managed-application-s-resource-group/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:27:16+00:00
- Modified: 2026-09-10T01:23:49+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

An Azure Managed Application can restrict the customer, the publisher, neither, or both; the deployed permission model matters.

## Potentially affected

Azure Managed Applications and their managed resource groups in customer subscriptions.

## DSE recommendation

Record the actual customer restriction and publisher access model before assigning maintenance or incident actions.

## Article

## Source facts

For Azure Managed Applications, publisher access and the customer’s deny assignment are optional. The default publisher-managed model grants publisher management access while restricting the customer through a deny assignment. A shared-access model instead gives both parties full access without that deny assignment.

Locked mode gives the publisher no access while retaining the customer’s restriction. Customer-managed mode gives the customer full management access and removes publisher access. A publisher assignment can also be permanent or limited to a specified period. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/overview).

## Applicability

Identify the application definition, managed resource group and deployed permission choices. Do not infer operational access solely from the subscription owner or the supplier’s support role.

## DSE recommendation

DSE recommends a responsibility record that pairs each maintenance action with an identity that is actually authorized to perform it. Include the route for requesting time-limited publisher access where that is the chosen model. Ask who can investigate and remediate a resource problem under the existing restriction before promising a response procedure. Escalate an unworkable ownership arrangement through the agreed application-management process.

## Verification

Inspect the current assignments and restrictions with an authorized reviewer. Test a permitted read or approved maintenance operation using the intended role, not an unrelated administrator. Record any time boundary on publisher access. If neither proposed operator can perform the required action, retain that as an unresolved responsibility gap rather than treating a successful application deployment as proof of maintainability.

## Official references

[Microsoft Learn: Overview of Azure Managed Applications](https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/overview). Source retrieved September 9, 2026.

## Primary reference

- Name: Overview of Azure Managed Applications - Azure Managed Applications | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/overview
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Identify who can maintain a managed application's resource group,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-280-identify-who-can-maintain-a-managed-application-s-resource-group/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
