Repository navigation
Allow users to restrict an az login session to one resource group or resource #34162
Copy link
Copy link
Open
Labels
ARMaz resource/group/lock/tag/deployment/policy/managementapp/account management-groupaz resource/group/lock/tag/deployment/policy/managementapp/account management-groupAccountaz login/accountaz login/accountAuto-AssignAuto assign by botAuto assign by botAzure CLI TeamThe command of the issue is owned by Azure CLI teamThe command of the issue is owned by Azure CLI teamact-codegen-extensibility-squadact-identity-squadcustomer-reportedIssues that are reported by GitHub users external to the Azure organization.Issues that are reported by GitHub users external to the Azure organization.feature-request
Milestone
Description
Activity
Thank you for opening this issue, we will look into it.
- addedcustomer-reportedIssues that are reported by GitHub users external to the Azure organization.Issues that are reported by GitHub users external to the Azure organization.Storageaz storageaz storageAuto-AssignAuto assign by botAuto assign by botAzure CLI TeamThe command of the issue is owned by Azure CLI teamThe command of the issue is owned by Azure CLI teamquestionThe issue doesn't require a change to the product in order to be resolved. Most issues start as thatThe issue doesn't require a change to the product in order to be resolved. Most issues start as thatARMaz resource/group/lock/tag/deployment/policy/managementapp/account management-groupaz resource/group/lock/tag/deployment/policy/managementapp/account management-groupAccountaz login/accountaz login/account
on Oct 2, 2026 - added and removedStorageaz storageaz storagequestionThe issue doesn't require a change to the product in order to be resolved. Most issues start as thatThe issue doesn't require a change to the product in order to be resolved. Most issues start as that
on Oct 5, 2026 microsoft-github-policy-service commented
on Oct 8, 2026 ContributorMore actions🔔 Routing this issue to @Azure/act-identity-squad.
microsoft-github-policy-service commented
on Oct 8, 2026 ContributorMore actions🔔 Routing this issue to @Azure/act-codegen-extensibility-squad.
Metadata
Metadata
Assignees
Labels
ARMaz resource/group/lock/tag/deployment/policy/managementapp/account management-groupaz resource/group/lock/tag/deployment/policy/managementapp/account management-groupAccountaz login/accountaz login/accountAuto-AssignAuto assign by botAuto assign by botAzure CLI TeamThe command of the issue is owned by Azure CLI teamThe command of the issue is owned by Azure CLI teamact-codegen-extensibility-squadact-identity-squadcustomer-reportedIssues that are reported by GitHub users external to the Azure organization.Issues that are reported by GitHub users external to the Azure organization.feature-request
Related command
az loginSuggested syntax below is illustrative, not an existing option.
Is your feature request related to a problem? Please describe.
My Azure user has legitimate access to several resource groups, including production systems. When working on development, I would like that specific login session to only have access to the development group.
This would be useful for ordinary terminal work, scripts, automation and agents. My account needing production access does not mean every work session I have needs it.
Read-only mode does not solve this. I need to write within the selected group, AND prevent reads of sensitive resources outside it.
Describe the solution you'd like
Could
az loginlet a user voluntarily narrow their existing permissions for one session, without administrator collaboration or changes to their normal role assignments?For example:
az login --restrict-to \ "/subscriptions/<subscription-id>/resourceGroups/development"Then ordinary commands would behave like this:
Resource-group scoping would already take us pretty far. Ideally, the same approach could allow selecting an individual resource within a group.
The restriction should be tied to the session's credentials and enforced by Azure. Changing command arguments, configuration or using the token directly should not bypass it. It should only reduce existing access, never grant additional permissions.
Describe alternatives you've considered
Additional context
This is a general CLI safety feature, not specifically an agent identity or MCP request. Agents are one use case where limiting the consequences of mistakes matters.
The restricted workflow should not silently fall back to unrestricted credentials. Other broad credentials accessible on the machine would still need to be kept away from the script or agent.
I am not sure whether Azure's existing authorization APIs support this. Could someone familiar with CLI authentication clarify whether it is feasible today, or which underlying Azure capability would be needed?
Related: #32974, global read-only mode. This request differs because it allows writes within the selected scope while also blocking sensitive reads outside it.