Security, Identity, and RBAC Reference
Production Azure SRE Agent designs must make identity and permission boundaries explicit.
Design Rules
- Prefer managed identity and secretless access.
- Use read-only scopes for diagnostics.
- Use narrowly scoped custom roles for remediation candidates.
- Separate connector permissions from Azure RBAC review.
- Treat OBO/user-delegated fallback as elevated risk that requires explicit human approval.
- Validate private-network and DNS paths before routing private workload incidents.
- Keep write-capable actions behind hooks, Review mode, and DA/PPA.
- Treat managed connector credentials as delegated credentials from the configuring user. Any agent user with access to the connector can invoke enabled operations through that credential.
- For private-network workloads, validate required domains, WebSocket access, DNS, proxy rules, and VNet-integrated execution before routing incidents through the agent.
Network Allow-List (verified 2026-08-10)
The agent's execution environment and portal require these domains for HTTP and WebSocket
traffic (https://learn.microsoft.com/azure/sre-agent/network-requirements):
| Domain | Purpose |
|---|---|
*.azuresre.ai |
Agent portal, API, real-time chat (WebSocket) |
sre.azure.com |
Agent management portal |
portal.azure.com |
Azure portal (Monitor, Logs, managed identity) |
api.applicationinsights.io |
Application Insights query API |
api.loganalytics.io / api.loganalytics.azure.com |
Log Analytics query API |
*.ods.opinsights.azure.com |
Log Analytics ingestion |
management.azure.com |
Azure Resource Manager |
login.microsoftonline.com / *.login.microsoft.com |
Microsoft Entra ID auth |
Zscaler and some corporate proxies block *.azuresre.ai by default: a blocked domain
presents as "portal won't load / chat unresponsive". Add it to the firewall allow list before
debugging anything else. The agent resource also exposes read-only outboundIpAddresses
for egress allow-listing.
No private-endpoint support exists on Microsoft.App/agents (verified via the resource
schema 2026-08-10; re-checked 2026-08-25); private connectivity is via VNet integration
(preview), configured with the agent's vnetConfiguration.subnetResourceId property. Do not design
around a private endpoint on the agent itself.
CMK: treat as unsupported until listed. Microsoft.App/agents does not appear in the
official "Services that support customer-managed keys" matrix
matrix (https://learn.microsoft.com/azure/security/fundamentals/encryption-customer-managed-keys-support,
page updated 2026-08-03, checked 2026-08-25). An exhaustive official support
matrix omitting the service is affirmative absence, not an open question; re-check only when
the service appears there.
Review Questions
- Which identity executes Azure actions?
- Which identity accesses repos, incident platforms, and observability systems?
- What happens if managed identity lacks permission?
- Which actions can modify production state?
- Where are connector tokens stored and rotated?
- How are private endpoints reached and logged?
- Which managed connector operations are set to
AllowversusAsk, and can any of them run in Autonomous mode? - Can the agent portal, data-plane endpoint, Application Insights, and required Azure domains be reached through corporate proxies and firewalls?