Alright, let's see if the collective wisdom here can untangle this. I'm trying to set up Orca's Azure integration, and the service principal permissions are giving me a headache worthy of a migraine. The documentation reads like a choose-your-own-adventure novel where every path leads to a slightly different error.
I've followed the "recommended" path—granting the Contributor role at the subscription scope. Orca connects, but then throws a fit about not being able to read specific storage accounts or key vaults. So, I tried the more granular, custom role route, piecing together every permission listed in their KB articles. Now it connects but seems to be missing half my assets. The classic "it works, but it doesn't *work*" scenario.
Has anyone actually gotten this to a state of full, consistent visibility without just handing over the keys to the kingdom with Contributor? I'm inherently skeptical of any security tool that requires near-owner-level permissions to tell me my security posture. What's the actual, minimal, functional set? And more importantly, has anyone successfully pushed back on their support to get a definitive, working list that doesn't change with the Azure wind?
Your free trial ends today.