• About Us
  • Contact Us
  • Advertise
  • Privacy Policy
  • Guest Post
No Result
View All Result
Digital Phablet
  • Home
  • NewsLatest
  • Technology
    • Education Tech
    • Home Tech
    • Office Tech
    • Fintech
    • Digital Marketing
  • Social Media
  • Gaming
  • Smartphones
  • AI
  • Reviews
  • Interesting
  • How To
  • Home
  • NewsLatest
  • Technology
    • Education Tech
    • Home Tech
    • Office Tech
    • Fintech
    • Digital Marketing
  • Social Media
  • Gaming
  • Smartphones
  • AI
  • Reviews
  • Interesting
  • How To
No Result
View All Result
Digital Phablet
No Result
View All Result

Home » How to Create a Custom Azure Role for Secondary Users in CosmosDB MongoDB

How to Create a Custom Azure Role for Secondary Users in CosmosDB MongoDB

DP Staff by DP Staff
November 20, 2025
in How To
Reading Time: 2 mins read
A A
How to Fix Azure Student Subscription Region Error
ADVERTISEMENT

Select Language:

If you’re working with Azure Cosmos DB for MongoDB vCore, you might notice that certain admin commands, like createRole, aren’t available. This is because those commands are managed directly by the service itself, and when you try to use them, you’ll see errors. This isn’t a mistake; it’s designed this way to simplify management. The vCore model streamlines administration by hiding some commands as part of its managed platform-as-a-service setup.

ADVERTISEMENT

You can read more about this in the official documentation here: https://learn.microsoft.com/en-us/azure/cosmos-db/mongodb/vcore/compatibility-and-feature-support.

For users connecting to the database as secondaries in the native (DocumentDB) mode, there are some clear limitations. Microsoft specifies that:

– Secondary accounts can only be created using the built-in admin account, through the createUser command.
– The roles available are limited to fixed options such as cluster-level read, write, or read-only permissions (like clusterAdmin, readWriteAnyDatabase, readAnyDatabase).
– Assigning roles to specific databases or collections isn’t supported; only cluster-level roles are available.

ADVERTISEMENT

This means that besides the fact that createRole isn’t supported, the vCore setup does not allow assigning roles based on databases or collections for secondary users.

You can create secondary users with the createUser command from the admin account, and assign them broad roles like:

– readAnyDatabase, which grants read-only access across all databases.
– readWriteAnyDatabase, for full read/write access across all databases.

However, this setup only grants access at the cluster level and doesn’t support more granular, per-database permissions.

To improve control, you can create custom Azure roles for your clusters and assign these to specific users or applications. These roles can help you manage who can connect or operate on each cluster, although they still don’t allow you to set permissions on individual databases or collections within a cluster. You can learn more about this here: https://learn.microsoft.com/en-us/azure/cosmos-db/mongodb/vcore/role-based-access-control.

If you need to restrict a user so that they can only write to database A, but not database B, the current best practice is to place each database in its own cluster. Then, you can assign the user only to the cluster that contains database A, giving them the appropriate permissions there, but no access to database B in its cluster.

ChatGPT ChatGPT Perplexity AI Perplexity Gemini AI Logo Gemini AI Grok AI Logo Grok AI
Google Banner
ADVERTISEMENT
DP Staff

DP Staff

Related Posts

Top 25 Countries with the Lowest Quality of Life in 2025

1.  Nigeria
2.  Bangla
Infotainment

Top 25 Countries with the Lowest Quality of Life in 2025

December 3, 2025
December 2025 The Forge Codes Revealed
Gaming

December 2025 The Forge Codes Revealed

December 3, 2025
Is the Battle Pass Worth Completing in Where Winds Meet?
Gaming

Is the Battle Pass Worth Completing in Where Winds Meet?

December 3, 2025
How to Beat Lucky Seventeen in Where Winds Meet by Completing and Solving
Gaming

How to Beat Lucky Seventeen in Where Winds Meet by Completing and Solving

December 3, 2025
Next Post
Why Bereketli Topraklar Starring Engin Akyürek Ended After Five Episodes

Why Bereketli Topraklar Starring Engin Akyürek Ended After Five Episodes

  • About Us
  • Contact Us
  • Advertise
  • Privacy Policy
  • Guest Post

© 2025 Digital Phablet

No Result
View All Result
  • Home
  • News
  • Technology
    • Education Tech
    • Home Tech
    • Office Tech
    • Fintech
    • Digital Marketing
  • Social Media
  • Gaming
  • Smartphones

© 2025 Digital Phablet