Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Note
To use this feature, your organization must have an Azure support plan with a minimum level of Developer.
The alternate email notification feature allows you to use alternate email addresses to receive Customer Lockbox notifications. This feature helps your organization receive Customer Lockbox for Microsoft Azure notifications when an Azure account isn't email-enabled or when a service principal is defined as the tenant admin or subscription owner.
Important
This feature sends Customer Lockbox notifications only to alternate email IDs. It doesn't allow alternate users to act as approvers for Customer Lockbox requests.
For example, Alice has the subscription owner role for subscription X, and she adds Bob's email address as an alternate email in her user profile. Bob has a reader role. When a Customer Lockbox request is created for a resource scoped to subscription X, Bob receives the email notification, but he can't approve or reject the Customer Lockbox request because he doesn't have the required privileges (subscription owner role).
Prerequisites
To use the Customer Lockbox for Microsoft Azure alternate email feature, you must have:
- A Microsoft Entra ID tenant that has Customer Lockbox for Microsoft Azure enabled.
- A Developer or higher Azure support plan.
- Role assignments:
- A user account with the Global Administrator, Privileged Authentication Administrator, or User Administrator role to update user settings.
- Optional: Owner or Azure Customer Lockbox Approver for Subscription role if you want to approve or reject Customer Lockbox requests.
Set up Customer Lockbox for Microsoft Azure alternate email notifications
To set up the Customer Lockbox for Microsoft Azure alternate email feature, follow these steps.
Go to the Azure portal.
Sign in with a user account that has Global Administrator, Privileged Authentication Administrator, or User Administrator role privileges.
Search for the user to add an alternate email address.
Note
The user must have Global Administrator, Owner, or Azure Customer Lockbox Approver for Subscription role privileges to act on Lockbox requests.
Enter the alternate email address in the text field, then select Save.
The Contact information tab shows the updated information with the alternate email:
If the primary Email field has a value, emails are sent only to that address. To send Lockbox email notifications to Other emails, clear the primary Email field.
When a Lockbox request is triggered and the user is identified as a Lockbox approver, the email notification is sent to the primary email if it has a value. If the primary email is empty, the notification is sent to other email addresses. These notifications tell the approver that Microsoft Support is trying to access a resource in their tenant, and the approver needs to sign in to the Azure portal to approve or reject the request. The following screenshot shows an example:
Known limitations
These limitations apply to this feature:
- The system sends duplicate emails if the primary email and other email values are the same.
- The system sends notifications to only the first email address in Other emails even if you configure multiple email addresses in the Other emails field.
- If you set the other email but don't set the primary email, the system sends two emails to the alternate email address.