Azure / Azure/azure-cli

Allow cross tenant subscription rest api

Open
#30,834 2 comments 1 reaction 1 assignee Claimed by @jiasli View on GitHub
act-identity-squad ARM Auto-Assign Azure CLI Team customer-reported needs-team-triage question
Dominant language
Python
Stars
4.6k
Forks
3.5k
Avg merge
3d 2h
Merged PRs (30d)
60

Description

**Related command**

`az rest --method post --uri "https://management.azure.com/subscriptions/customersubscription/resourceGroups/rg-managedapp/providers/Microsoft.Solutions/applications/mymanagedapp/listTokens?api-version=2018-09-01-preview"`

**Is your feature request related to a problem? Please describe.**

I have a managed app published, I want to retrieve the managed identity access token. This must be done with a publisher identity (or a managed identity in the managed resource group, but that is not the scenario I am playing). Unfortunately `az rest` first checks if the subscription is known before submitting the rest http call. The publisher identity does not see this subscription as it is connected with the consumer tenant.

**Describe the solution you'd like**

I would like to have a flag to skip the subscription check.

**Describe alternatives you've considered**

With `az account get-access-token` I can get a token, and then use regular `curl`.

**Additional context**

See https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/publish-managed-identity#accessing-the-managed-identity-token where this is documented.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.