Foreign Principal Role for Azure Support
This document is intended to apply the "Foreign Principal Role", which is required to pass Microsoft's validation tool. This tool is used as an extra security checkpoint to ensure the case was created from the associated Tenant ID and Foreign Principal Role. The Azure CLI script, provided below, will need to be run against all Azure Subs that will be supported under this contract.
There are two steps to complete this process. The first step is adding a reseller relationship and the second is running the Foreign Principle Role through Azure CLI.
Click the following link to accept this invitation and authorize Shi International Corp. to be your Microsoft Cloud Solution Provider and accept the Microsoft Customer Agreement:
Note: User with Global Admin permission is required to accept the relationship
The Azure CLI will be applied to SHI's "AdminAgent" security group, which possesses the least privileged role required to submit a Microsoft support case. This will need to be run by the client with both Global Admin and Owner roles over the Azure Sub.
This is SHI's "AdminAgents" AD security group ID: f628f068-9a43-4bcc-9cd9-fcf6c6582d04 that has already been added to the script below.
You may place more than one Azure Sub ID at a time by using a comma to separate them.
Here is the Azure CLI to use:
az role assignment create --role "Support Request Contributor" --assignee-object-id f628f068-9a43-4bcc-9cd9-fcf6c6582d04 --scope "/subscriptions/add Subscription ID(s) here" --assignee-principal-type "ForeignGroup"
Access to all Subscriptions
Use this Azure CLI script in the scenario customer wants to give us access to all subscriptions across all management groups: #!/bin/bash # Get all accessible subscriptions subscriptions=$(az account list --query "[].id" -o tsv) # Loop through each subscription for subscription in $subscriptions; do echo "Processing subscription: $subscription" # Set the current subscription context az account set --subscription "$subscription" # Assign role for TenantAdmins az role assignment create \ --assignee "f628f068-9a43-4bcc-9cd9-fcf6c6582d04" \ --role "Support Request Contributor" \ --scope "/subscriptions/$subscription" done
If your tenant is listed in the Partner Center other than US use the following:
UK Object ID: fb53b718-b11f-4e4e-83cf-e165e18ea97b
Canada Object ID: eca2ce54-5c58-4a9c-b246-371b0cf76a4d
Ireland Object ID: 7faac1bc-b61a-4cd9-9552-88845ad13def
Gov Object ID: 3915d5bc-3858-473d-b4fd-eaea49a50b38