Identify who can maintain a managed application's resource group

An Azure Managed Application can restrict the customer, the publisher, neither, or both; the deployed permission model matters.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

An Azure Managed Application can restrict the customer, the publisher, neither, or both; the deployed permission model matters.

Potentially affected

Azure Managed Applications and their managed resource groups in customer subscriptions.

DSE recommendation

Record the actual customer restriction and publisher access model before assigning maintenance or incident actions.

Source facts

For Azure Managed Applications, publisher access and the customer’s deny assignment are optional. The default publisher-managed model grants publisher management access while restricting the customer through a deny assignment. A shared-access model instead gives both parties full access without that deny assignment.

Locked mode gives the publisher no access while retaining the customer’s restriction. Customer-managed mode gives the customer full management access and removes publisher access. A publisher assignment can also be permanent or limited to a specified period. Microsoft Learn.

Applicability

Identify the application definition, managed resource group and deployed permission choices. Do not infer operational access solely from the subscription owner or the supplier’s support role.

DSE recommendation

DSE recommends a responsibility record that pairs each maintenance action with an identity that is actually authorized to perform it. Include the route for requesting time-limited publisher access where that is the chosen model. Ask who can investigate and remediate a resource problem under the existing restriction before promising a response procedure. Escalate an unworkable ownership arrangement through the agreed application-management process.

Verification

Inspect the current assignments and restrictions with an authorized reviewer. Test a permitted read or approved maintenance operation using the intended role, not an unrelated administrator. Record any time boundary on publisher access. If neither proposed operator can perform the required action, retain that as an unresolved responsibility gap rather than treating a successful application deployment as proof of maintainability.

Official references

Microsoft Learn: Overview of Azure Managed Applications. Source retrieved September 9, 2026.

Primary reference

Review the official source

Overview of Azure Managed Applications - Azure Managed Applications | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE