I have a primary Azure account and subscription in a “Default” Entra ID tenant. In that subscription, I added a new External ID tenant for use with a customer facing mobile app. Also in the main tenant, I added a Microsoft Health Data Services workspace with a FHIR Service. See https://learn.microsoft.com/en-us/azure/healthcare-apis/fhir/overview
I cannot find any way to add roles to my users in the External ID tenant that will allow read/write access to the FHIR Service resource. I also configured an Application in the External ID tenant, and cannot find a way to authorize it to access a resource in the main tenant.
I am relatively new to both Azure and Entra. Am I missing something fundamental in my understanding? Apparently, I am not allowed to add the Health Data Services resource directly into my External ID tenant.
This appears to be similar configuration as described in another post, but I do not have a dedicated back-end API resource other than the FHIR Service provided by Microsoft.
Questions around Entra External ID and deploying resources
Thanks for any insight!
Dave
Dave Carlson is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.