Lighthouse offer and Managed Identities permissions
Hi, I am trying to assign the Contributor role over a Lighthouse managed subscription to a System Managed Identity (an Automation account). According to the documentation: "The User Access Administrator role is supported, but only for the limited…
Can a customer's same resource group be managed by multiple MSSP in Azure Lighthouse?
A customer is currently migrating from another MSSP Lighthouse to our Lighthouse. I'm wondering how to make the migration smoother. It would be great if one customer could subscribe to multiple Lighthouses. If not, they will need to migrate out and then…
Broken management of Defender EASM via Azure Lighthouse
We try to manage Defender EASM from a customer using Azure Lighthoure. We have Contributor Rights to the Customer Subscription using Azure Lighthouse ARM Template. Everything in the Customer Subscription can be managed fine, but management of Defender…

Which Entra Role is Required to Manage Users in Microsoft 365 Lighthouse?
Hello all, I read this article: https://learn.microsoft.com/en-us/microsoft-365/lighthouse/m365-lighthouse-overview-of-permissions?view=o365-worldwide It states that I need an Entra Role to manage (search, view, etc.) users in Lighthouse. However, I…
Need to delegate a subscription to another tenant.
I have a subscription in one tenant (lets call it Tenant A) and a Dynamics Sandbox environment hosted in a different tenant (Tenant B). I am trying to delegate my subscription from Tenant A to Tenant B so that I can use the same subscription to implement…
How to send different tenant's Azure WAF log to tenant with Sentinel Configured?
Hello, I have 2 tenants. A tenant : WAF configured (Sentinel x) B tenant : Sentinel configured( WAF x) I would like to analyze A's logs in tenant B's sentinel. How can I configure? I think I should configure Azure lighthouse, is it right? If not,…
Azure Monitor in External Tenant
Hi, We are setting up an Entra External ID tenant to house external users of a web app that we host. I presently stream our internal diagnostics logs to an Event Hub in our workforce tenant and then to an IDR. I found this article and was successful at…
Azure Lighthouse Service REST API
We have many subscriptions, and some of them are managed by the lighthouse service. We would like to know which of them are managed by lighthouse using only rest api. How can we find out?
Issues with Role-Based Deletion Restriction & Locks in Azure Lighthouse
I need support for an Azure Lighthouse environment. I set up a test environment with two Azure accounts—one as a service provider and the other as a customer. The Azure Lighthouse environment was successfully set up on both accounts. I have two security…
How can I use client dashboards with azure lighthouse?
Hello, I work for a service provider company and I need help with monitoring my clients dashboards. I need to have multiple client dashboards on my azure tenant, I did connect our tenant (service provider) with each one of our client's tenants with the…
Is it possible to use Lighthouse with AME/PME tenant?
Is it possible to use Lighthouse with AME/PME tenant? i.e. project multiple customers resources to AME or PME?
As a CSP, did you find an "efficient" solution for managing customer access? (Azure + M365)
Hello, As a Cloud Service Provider (CSP), we are in search of a comprehensive solution that can fully support our needs in managing our customers' Azure and Microsoft 365 tenants. Our customers may utilize Azure, Microsoft 365, or both, and we need a…
Lighthouse Offer - I cannot add System Managed Identities to my customers Logic Apps
I have my roles delegated, I am in the correct AD groups on my tenant. However, when I got into a Logic App, and try to assign a System Assigned Managed Identity, I keep on getting the following error message: Failed to add Resource as Microsoft…
Use Azure Policy at scale at an MSP
Hi there, I am starting to use Azure Lighthouse and Policy at a MSP. I want to use Azure Policy to manage all the delegated customer subscriptions. It seems that there is no built-in option to just push initiatives and policies to subscriptions in…
Managing Customer Sentinel through Azure Lighthouse
Hi Experts, Please help. I have registered our customer on our Azure Lighthouse. I can see their Sentinel with data in it, but when I try to check data connectors, I am getting below errors: Can't see any connector connected, but when customer Global…
Navigating Azure Arc Integration for Windows Server 2012: Key Considerations and Potential Pitfalls
Urgent : We have an on-premises Windows Server 2012 serving as a service provider for a client's production application. We’re considering mapping it to Azure Arc to obtain Windows Update Extended Security Updates (ESU). Could you help us understand the…
How to fix error when deploying managed service template
Hey, I'm having this problem after deleting my first successful attempt at creating a managed service template. After deleting my first template that validated successfully and was created, but later deleted because of a mistake. I am unable to validate…
Azure Lighthouse - Assigning IAM permissions to users
Aloha, all: My MSP team and I have been using both Azure and M365 Lighthouse for a few months now. Now we're pretty comfortable with it, we've an ongoing project to remove all our native accounts from customer environments. Going through the benefits and…

cross tenant alerting
Hi,following on from this notification https://azure.microsoft.com/en-us/updates/sending-a-log-search-alert-with-cross-tenant-target-resource-will-no-longer-be-supported/ the part 'As of March 15, 2024, this behavior will change and sending a log search…
Azure Ligthouse User Access Admin group not working
In Azure AD I am assigned to an Azure Lighthouse group that is supposed to give me the 'User Access Administrator' role to all subscriptions from another tenant that is enrolled in Lighthouse. When I view my access on the subscriptions, I can see that my…