An administrator is configuring access control for a Log Analytics workspace named Workspace1. The workspace collects diagnostic and performance logs from multiple Azure Virtual Machines deployed across different resource groups.
You need to ensure that application owners can run KQL queries to view log data only for their respective virtual machines. The application owners must not be able to view logs for virtual machines they do not own.
Which two actions should you perform? (Select TWO.)
- Configure the access control mode of Workspace1 to Use resource or workspace permissions.Cevap
- Assign the Reader role to the application owners on their respective virtual machines.Cevap
- CConfigure the access control mode of Workspace1 to Require workspace permissions.
- DAssign the Log Analytics Reader role to the application owners on Workspace1.
Cevap
Configure the access control mode of Workspace1 to 'Use resource or workspace permissions' and assign the 'Reader' role to the application owners on their respective virtual machines.
To restrict users to viewing logs only for the virtual machines they own, the workspace must be configured for resource-context access. This is done by selecting the 'Use resource or workspace permissions' access control mode. Additionally, users must be granted read access to the specific resources, which can be accomplished by assigning the Reader role at the scope of their respective virtual machines.
Adım Adım Çözüm
Anahtar Kavram
Log Analytics Workspace Access Control Modes (resource-context vs workspace-context)
Tahmini Süre:2m 0s