Skip to content

Commit 489b675

Browse files
authored
Update RBAC samples 2510 (#160)
## Purpose Update the RBAC samples to include the new 2510 permissions ## Does this introduce a breaking change? <!-- Mark one with an "x". --> ``` [ ] Yes [x] No ``` ## Pull Request Type What kind of change does this Pull Request introduce? <!-- Please check the one that applies to this PR using "x". --> ``` [ ] Bugfix [ ] Feature [ ] Code style update (formatting, local variables) [ ] Refactoring (no functional changes, no api changes) [x] Documentation content changes [ ] Other... Please describe: ```
1 parent 7289c4a commit 489b675

File tree

8 files changed

+38
-51
lines changed

8 files changed

+38
-51
lines changed

samples/custom-rbac/Administrator.json

Lines changed: 9 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -16,25 +16,13 @@
1616
"Microsoft.Dashboard/grafana/read",
1717
"Microsoft.Dashboard/grafana/write",
1818
"Microsoft.Dashboard/register/action",
19-
"Microsoft.DeviceRegistry/assetEndpointProfiles/delete",
20-
"Microsoft.DeviceRegistry/assetEndpointProfiles/read",
21-
"Microsoft.DeviceRegistry/assetEndpointProfiles/write",
22-
"Microsoft.DeviceRegistry/assets/delete",
23-
"Microsoft.DeviceRegistry/assets/read",
24-
"Microsoft.DeviceRegistry/assets/write",
25-
"Microsoft.DeviceRegistry/discoveredAssetEndpointProfiles/delete",
26-
"Microsoft.DeviceRegistry/discoveredAssetEndpointProfiles/read",
27-
"Microsoft.DeviceRegistry/discoveredAssetEndpointProfiles/write",
28-
"Microsoft.DeviceRegistry/discoveredAssets/delete",
29-
"Microsoft.DeviceRegistry/discoveredAssets/read",
30-
"Microsoft.DeviceRegistry/discoveredAssets/write",
31-
"Microsoft.DeviceRegistry/register/action",
32-
"Microsoft.DeviceRegistry/schemaRegistries/read",
33-
"Microsoft.DeviceRegistry/schemaRegistries/schemas/read",
34-
"Microsoft.DeviceRegistry/schemaRegistries/schemas/schemaVersions/read",
35-
"Microsoft.DeviceRegistry/schemaRegistries/schemas/schemaVersions/write",
36-
"Microsoft.DeviceRegistry/schemaRegistries/schemas/write",
37-
"Microsoft.DeviceRegistry/schemaRegistries/write",
19+
"Microsoft.DeviceRegistry/Assets/*",
20+
"Microsoft.DeviceRegistry/AssetEndpointProfiles/*",
21+
"Microsoft.DeviceRegistry/Namespaces/Assets/*",
22+
"Microsoft.DeviceRegistry/Namespaces/Devices/*",
23+
"Microsoft.DeviceRegistry/Namespaces/DiscoveredAssets/*",
24+
"Microsoft.DeviceRegistry/Namespaces/DiscoveredDevices/*",
25+
"Microsoft.DeviceRegistry/SchemaRegistries/*",
3826
"Microsoft.Edge/sites/read",
3927
"Microsoft.Edgeorder/addresses/read",
4028
"Microsoft.ExtendedLocation/customLocations/deploy/action",
@@ -53,8 +41,8 @@
5341
"Microsoft.KeyVault/vaults/read",
5442
"Microsoft.KeyVault/vaults/write",
5543
"Microsoft.Kubernetes/connectedClusters/listClusterUserCredential/action",
56-
"Microsoft.Kubernetes/connectedclusters/read",
57-
"Microsoft.Kubernetes/connectedclusters/write",
44+
"Microsoft.Kubernetes/connectedClusters/read",
45+
"Microsoft.Kubernetes/connectedClusters/write",
5846
"Microsoft.Kubernetes/register/action",
5947
"Microsoft.KubernetesConfiguration/extensionTypes/read",
6048
"Microsoft.KubernetesConfiguration/extensions/operations/read",

samples/custom-rbac/Asset Administrator.json

Lines changed: 6 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -8,14 +8,12 @@
88
"permissions": [
99
{
1010
"actions": [
11-
"Microsoft.DeviceRegistry/assetEndpointProfiles/read",
12-
"Microsoft.DeviceRegistry/assets/delete",
13-
"Microsoft.DeviceRegistry/assets/read",
14-
"Microsoft.DeviceRegistry/assets/write",
15-
"Microsoft.DeviceRegistry/discoveredAssetEndpointProfiles/read",
16-
"Microsoft.DeviceRegistry/discoveredAssets/delete",
17-
"Microsoft.DeviceRegistry/discoveredAssets/read",
18-
"Microsoft.DeviceRegistry/discoveredAssets/write",
11+
"Microsoft.DeviceRegistry/Assets/*",
12+
"Microsoft.DeviceRegistry/AssetEndpointProfiles/read",
13+
"Microsoft.DeviceRegistry/Namespaces/Assets/*",
14+
"Microsoft.DeviceRegistry/Namespaces/Devices/read",
15+
"Microsoft.DeviceRegistry/Namespaces/DiscoveredAssets/*",
16+
"Microsoft.DeviceRegistry/Namespaces/DiscoveredDevices/read",
1917
"Microsoft.Edge/sites/read",
2018
"Microsoft.Edgeorder/addresses/read",
2119
"Microsoft.ExtendedLocation/customLocations/deploy/action",

samples/custom-rbac/Asset Viewer.json

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,9 @@
88
"permissions": [
99
{
1010
"actions": [
11-
"Microsoft.DeviceRegistry/assets/read",
12-
"Microsoft.DeviceRegistry/discoveredAssets/read",
11+
"Microsoft.DeviceRegistry/Assets/read",
12+
"Microsoft.DeviceRegistry/Namespaces/Assets/read",
13+
"Microsoft.DeviceRegistry/Namespaces/DiscoveredAssets/read",
1314
"Microsoft.Edge/sites/read",
1415
"Microsoft.Edgeorder/addresses/read",
1516
"Microsoft.ExtendedLocation/customLocations/enabledresourcetypes/read",

samples/custom-rbac/Data Flow Administrator.json

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,9 @@
88
"permissions": [
99
{
1010
"actions": [
11-
"Microsoft.DeviceRegistry/assets/read",
12-
"Microsoft.DeviceRegistry/discoveredAssets/read",
11+
"Microsoft.DeviceRegistry/Assets/read",
12+
"Microsoft.DeviceRegistry/Namespaces/Assets/read",
13+
"Microsoft.DeviceRegistry/Namespaces/DiscoveredAssets/read",
1314
"Microsoft.DeviceRegistry/schemaRegistries/read",
1415
"Microsoft.DeviceRegistry/schemaRegistries/schemas/read",
1516
"Microsoft.DeviceRegistry/schemaRegistries/schemas/schemaVersions/read",

samples/custom-rbac/Asset Endpoint Administrator.json renamed to samples/custom-rbac/Device Administrator.json

Lines changed: 4 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,19 +1,15 @@
11
{
22
"properties": {
3-
"roleName": "Azure IoT Operations Asset Endpoint Administrator",
4-
"description": "View, create, edit and delete Azure IoT Operations Asset Endpoints",
3+
"roleName": "Azure IoT Operations Device Administrator",
4+
"description": "View, create, edit and delete Azure IoT Operations Devices",
55
"assignableScopes": [
66
"/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"
77
],
88
"permissions": [
99
{
1010
"actions": [
11-
"Microsoft.DeviceRegistry/assetEndpointProfiles/delete",
12-
"Microsoft.DeviceRegistry/assetEndpointProfiles/read",
13-
"Microsoft.DeviceRegistry/assetEndpointProfiles/write",
14-
"Microsoft.DeviceRegistry/discoveredAssetEndpointProfiles/delete",
15-
"Microsoft.DeviceRegistry/discoveredAssetEndpointProfiles/read",
16-
"Microsoft.DeviceRegistry/discoveredAssetEndpointProfiles/write",
11+
"Microsoft.DeviceRegistry/Namespaces/Devices/*",
12+
"Microsoft.DeviceRegistry/Namespaces/DiscoveredDevices/*",
1713
"Microsoft.Edge/sites/read",
1814
"Microsoft.Edgeorder/addresses/read",
1915
"Microsoft.ExtendedLocation/customLocations/deploy/action",

samples/custom-rbac/Asset Endpoint Viewer.json renamed to samples/custom-rbac/Device Viewer.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,15 @@
11
{
22
"properties": {
3-
"roleName": "Azure IoT Operations Asset Endpoint Viewer",
4-
"description": "View Azure IoT Operations Asset Endpoint list and details",
3+
"roleName": "Azure IoT Operations Device Viewer",
4+
"description": "View Azure IoT Operations Device list and details",
55
"assignableScopes": [
66
"/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"
77
],
88
"permissions": [
99
{
1010
"actions": [
11-
"Microsoft.DeviceRegistry/assetEndpointProfiles/read",
12-
"Microsoft.DeviceRegistry/discoveredAssetEndpointProfiles/read",
11+
"Microsoft.DeviceRegistry/Namespaces/Devices/read",
12+
"Microsoft.DeviceRegistry/Namespaces/DiscoveredDevices/read",
1313
"Microsoft.Edge/sites/read",
1414
"Microsoft.Edgeorder/addresses/read",
1515
"Microsoft.ExtendedLocation/customLocations/enabledresourcetypes/read",

samples/custom-rbac/Instance Administrator.json

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,8 +9,9 @@
99
{
1010
"actions": [
1111
"Microsoft.Authorization/roleAssignments/write",
12-
"Microsoft.DeviceRegistry/assets/read",
13-
"Microsoft.DeviceRegistry/discoveredAssets/read",
12+
"Microsoft.DeviceRegistry/Assets/read",
13+
"Microsoft.DeviceRegistry/Namespaces/Assets/read",
14+
"Microsoft.DeviceRegistry/Namespaces/DiscoveredAssets/read",
1415
"Microsoft.DeviceRegistry/register/action",
1516
"Microsoft.DeviceRegistry/schemaRegistries/read",
1617
"Microsoft.DeviceRegistry/schemaRegistries/schemas/read",

samples/custom-rbac/Viewer.json

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,10 +8,12 @@
88
"permissions": [
99
{
1010
"actions": [
11-
"Microsoft.DeviceRegistry/assetEndpointProfiles/read",
12-
"Microsoft.DeviceRegistry/assets/read",
13-
"Microsoft.DeviceRegistry/discoveredAssetEndpointProfiles/read",
14-
"Microsoft.DeviceRegistry/discoveredAssets/read",
11+
"Microsoft.DeviceRegistry/Assets/read",
12+
"Microsoft.DeviceRegistry/AssetEndpointProfiles/read",
13+
"Microsoft.DeviceRegistry/Namespaces/Assets/read",
14+
"Microsoft.DeviceRegistry/Namespaces/DiscoveredAssets/read",
15+
"Microsoft.DeviceRegistry/Namespaces/Devices/read",
16+
"Microsoft.DeviceRegistry/Namespaces/DiscoveredDevices/read",
1517
"Microsoft.Edge/sites/read",
1618
"Microsoft.Edgeorder/addresses/read",
1719
"Microsoft.ExtendedLocation/customLocations/enabledresourcetypes/read",

0 commit comments

Comments
 (0)