For the complete documentation index, see llms.txt. This page is also available as Markdown.

Requesting Microsoft Azure access

How to request just-in-time access to Microsoft Azure subscriptions, resources, and roles through P0 via Slack, Teams, Webex, the P0 CLI, or the P0 dashboard.

Requesting from Slack or through p0.app

Open up the p0 modal using /p0 request in Slack or with the Request Access feature in p0.app and select "Microsoft Azure" as the resource.

P0 Security Microsoft Azure Just In Time Resource Select

Then select which subscription that contains the items you'd like to request access to

P0 Security Microsoft Azure Just In Time Subscription Select

Then select the individual resource you'd like to request access to

P0 Security Microsoft Azure Just In Time Resource Select

Finally, select which role you would like to be granted on the resource you selected

P0 Security Microsoft Azure Just In Time Role Select

P0 auto-completes as you start typing out the resource or role. Once you select the policy / group you need, you can optionally add a reason for the approver(s) within p0, then submit the request. If an existing policy / group isn't shown in the auto-complete results, it may be filtered out by access policies.

What happens next

Once you make the request, you should get a Slack message from the p0 bot showing your request. There will also be a message to the approvers in the Slack channel designated by your org admin, requesting access.

  1. If your request is approved, when you get a message that it has been approved, that means you should already have access provisioned, as that happens all at the same time.

  2. If you are on-call (on a PagerDuty schedule), and your org admin has enabled PagerDuty routing, your access may be automatically approved for 1 hour.

  3. After your request is approved, there will be a “relinquish” button for you to let go of your permissions early if you finish what you wanted to do before the expiration date (so you can let go of unneeded permissions).

  4. If you wait for the access to expire, you will get a message that it has expired once it does.

  5. If your request is denied, you'll get a message letting you know.

Last updated