Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update register-existing-system.md #125733

Open
wants to merge 3 commits into
base: main
Choose a base branch
from
Open
Changes from 2 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions articles/sap/center-sap-solutions/register-existing-system.md
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,9 @@ When you register a system with Azure Center for SAP solutions, the following re
- Use a [**Service tags**](../../virtual-network/service-tags-overview.md) to allow connectivity
- Use a [Service tags with regional scope](../../virtual-network/service-tags-overview.md) to allow connectivity to resources in the same region as the VMs.
- Allowlist the region-specific IP addresses for Azure Storage, ARM and Microsoft Entra ID.
- For Windows system, ACSS requires outbound connectivity to www.microsoft.com
- ACSS Health and Status script are signed with a certificate whose certificate revocation list URL points to www.microsoft.com therefore for windows system, ACSS requires outbound connectivity to www.microsoft.com
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For better clarity to customers, please make the update to the documentation indicating that ACSS runs PowerShell scripts through a VM extension to provide various capabilities. PS scripts are signed by Microsoft. On Windows OS, the script signature is validated and for the validation to be successful the URL must be allow-listed. Otherwise, functionalities in ACSS will not work as expected.

- If you use a firewall, you can add an outbound rule to an endpoint wwww.microsoft.com port 80
- ACSS deploys a **managed storage account** into your subscription, for each SAP system being registered. You have the option to choose [**network access**](#managed-storage-account-network-access-settings) setting for the storage account.
- If you choose network access from specific Virtual Networks option, then you need to make sure **Microsoft.Storage** service endpoint is enabled on all subnets in which the SAP system Virtual Machines exist. This service endpoint is used to enable access from the SAP virtual machine to the managed storage account, to access the scripts that ACSS runs on the VM extension.
- If you choose public network access option, then you need to grant access to Azure Storage accounts from the virtual network where the SAP system exists.
Expand Down