Skip to content

Commit 081e5e5

Browse files
authored
Merge pull request #89744 from rolyon/rolyon-rbac-roles-sept
[Azure RBAC] Updates to roles and operations for September
2 parents fece4ec + 6aae936 commit 081e5e5

File tree

2 files changed

+235
-45
lines changed

2 files changed

+235
-45
lines changed

articles/role-based-access-control/built-in-roles.md

Lines changed: 90 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ ms.devlang:
1212
ms.topic: reference
1313
ms.tgt_pltfrm:
1414
ms.workload: identity
15-
ms.date: 08/27/2019
15+
ms.date: 09/25/2019
1616
ms.author: rolyon
1717
ms.reviewer: bagovind
1818

@@ -56,6 +56,9 @@ The following table provides a brief description of each built-in role. Click th
5656
| [Azure Kubernetes Service Cluster Admin Role](#azure-kubernetes-service-cluster-admin-role) | List cluster admin credential action. |
5757
| [Azure Kubernetes Service Cluster User Role](#azure-kubernetes-service-cluster-user-role) | List cluster user credential action. |
5858
| [Azure Maps Data Reader (Preview)](#azure-maps-data-reader-preview) | Grants access to read map related data from an Azure maps account. |
59+
| [Azure Sentinel Contributor](#azure-sentinel-contributor) | Azure Sentinel Contributor |
60+
| [Azure Sentinel Reader](#azure-sentinel-reader) | Azure Sentinel Reader |
61+
| [Azure Sentinel Responder](#azure-sentinel-responder) | Azure Sentinel Responder |
5962
| [Azure Service Bus Data Owner](#azure-service-bus-data-owner) | Allows for full access to Azure Service Bus resources. |
6063
| [Azure Service Bus Data Receiver](#azure-service-bus-data-receiver) | Allows for receive access to Azure Service Bus resources. |
6164
| [Azure Service Bus Data Sender](#azure-service-bus-data-sender) | Allows for send access to Azure Service Bus resources. |
@@ -174,7 +177,7 @@ The following table provides a brief description of each built-in role. Click th
174177
> [!div class="mx-tableFixed"]
175178
> | | |
176179
> | --- | --- |
177-
> | **Description** | Lets you manage everything except access to resources. |
180+
> | **Description** | Lets you manage everything except granting access to resources. |
178181
> | **Id** | b24988ac-6180-42a0-ab88-20f7382dd24c |
179182
> | **Actions** | |
180183
> | * | Create and manage resources of all types |
@@ -644,6 +647,89 @@ The following table provides a brief description of each built-in role. Click th
644647
> | **NotDataActions** | |
645648
> | *none* | |
646649
650+
## Azure Sentinel Contributor
651+
> [!div class="mx-tableFixed"]
652+
> | | |
653+
> | --- | --- |
654+
> | **Description** | Azure Sentinel Contributor |
655+
> | **Id** | ab8e14d6-4a74-4a29-9ba8-549422addade |
656+
> | **Actions** | |
657+
> | Microsoft.SecurityInsights/* | |
658+
> | Microsoft.OperationalInsights/workspaces/analytics/query/action | Search using new engine. |
659+
> | Microsoft.OperationalInsights/workspaces/read | Gets an existing workspace |
660+
> | Microsoft.OperationalInsights/workspaces/savedSearches/* | |
661+
> | Microsoft.OperationsManagement/solutions/read | Get exiting OMS solution |
662+
> | Microsoft.OperationalInsights/workspaces/query/read | Run queries over the data in the workspace |
663+
> | Microsoft.OperationalInsights/workspaces/dataSources/read | Get datasources under a workspace. |
664+
> | Microsoft.Insights/workbooks/* | |
665+
> | Microsoft.Authorization/*/read | Read roles and role assignments |
666+
> | Microsoft.Insights/alertRules/* | Create and manage Insights alert rules |
667+
> | Microsoft.Resources/deployments/* | Create and manage resource group deployments |
668+
> | Microsoft.Resources/subscriptions/resourceGroups/read | Gets or lists resource groups. |
669+
> | Microsoft.Support/* | Create and manage support tickets |
670+
> | **NotActions** | |
671+
> | *none* | |
672+
> | **DataActions** | |
673+
> | *none* | |
674+
> | **NotDataActions** | |
675+
> | *none* | |
676+
677+
## Azure Sentinel Reader
678+
> [!div class="mx-tableFixed"]
679+
> | | |
680+
> | --- | --- |
681+
> | **Description** | Azure Sentinel Reader |
682+
> | **Id** | 8d289c81-5878-46d4-8554-54e1e3d8b5cb |
683+
> | **Actions** | |
684+
> | Microsoft.SecurityInsights/*/read | |
685+
> | Microsoft.OperationalInsights/workspaces/analytics/query/action | Search using new engine. |
686+
> | Microsoft.OperationalInsights/workspaces/read | Gets an existing workspace |
687+
> | Microsoft.OperationalInsights/workspaces/savedSearches/read | Gets a saved search query |
688+
> | Microsoft.OperationsManagement/solutions/read | Get exiting OMS solution |
689+
> | Microsoft.OperationalInsights/workspaces/query/read | Run queries over the data in the workspace |
690+
> | Microsoft.OperationalInsights/workspaces/dataSources/read | Get datasources under a workspace. |
691+
> | Microsoft.Insights/workbooks/read | Read a workbook |
692+
> | Microsoft.Authorization/*/read | Read roles and role assignments |
693+
> | Microsoft.Insights/alertRules/* | Create and manage Insights alert rules |
694+
> | Microsoft.Resources/deployments/* | Create and manage resource group deployments |
695+
> | Microsoft.Resources/subscriptions/resourceGroups/read | Gets or lists resource groups. |
696+
> | Microsoft.Support/* | Create and manage support tickets |
697+
> | **NotActions** | |
698+
> | *none* | |
699+
> | **DataActions** | |
700+
> | *none* | |
701+
> | **NotDataActions** | |
702+
> | *none* | |
703+
704+
## Azure Sentinel Responder
705+
> [!div class="mx-tableFixed"]
706+
> | | |
707+
> | --- | --- |
708+
> | **Description** | Azure Sentinel Responder |
709+
> | **Id** | 3e150937-b8fe-4cfb-8069-0eaf05ecd056 |
710+
> | **Actions** | |
711+
> | Microsoft.SecurityInsights/*/read | |
712+
> | Microsoft.SecurityInsights/cases/* | |
713+
> | Microsoft.OperationalInsights/workspaces/analytics/query/action | Search using new engine. |
714+
> | Microsoft.OperationalInsights/workspaces/read | Gets an existing workspace |
715+
> | Microsoft.OperationalInsights/workspaces/dataSources/read | Get datasources under a workspace. |
716+
> | Microsoft.OperationalInsights/workspaces/savedSearches/read | Gets a saved search query |
717+
> | Microsoft.OperationsManagement/solutions/read | Get exiting OMS solution |
718+
> | Microsoft.OperationalInsights/workspaces/query/read | Run queries over the data in the workspace |
719+
> | Microsoft.OperationalInsights/workspaces/dataSources/read | Get datasources under a workspace. |
720+
> | Microsoft.Insights/workbooks/read | Read a workbook |
721+
> | Microsoft.Authorization/*/read | Read roles and role assignments |
722+
> | Microsoft.Insights/alertRules/* | Create and manage Insights alert rules |
723+
> | Microsoft.Resources/deployments/* | Create and manage resource group deployments |
724+
> | Microsoft.Resources/subscriptions/resourceGroups/read | Gets or lists resource groups. |
725+
> | Microsoft.Support/* | Create and manage support tickets |
726+
> | **NotActions** | |
727+
> | *none* | |
728+
> | **DataActions** | |
729+
> | *none* | |
730+
> | **NotDataActions** | |
731+
> | *none* | |
732+
647733
## Azure Service Bus Data Owner
648734
> [!div class="mx-tableFixed"]
649735
> | | |
@@ -1763,7 +1849,7 @@ The following table provides a brief description of each built-in role. Click th
17631849
> | Microsoft.Web/customApis/* | Creates and manages a Custom API. |
17641850
> | Microsoft.Web/serverFarms/join/action | |
17651851
> | Microsoft.Web/serverFarms/read | Get the properties on an App Service Plan |
1766-
> | Microsoft.Web/sites/functions/listSecrets/action | List Secrets Web Apps Functions. |
1852+
> | Microsoft.Web/sites/functions/listSecrets/action | List Function secrets. |
17671853
> | **NotActions** | |
17681854
> | *none* | |
17691855
> | **DataActions** | |
@@ -2274,6 +2360,7 @@ The following table provides a brief description of each built-in role. Click th
22742360
> | Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/recoveryPoints/read | Read any Replication Recovery Points |
22752361
> | Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/repairReplication/action | Repair replication |
22762362
> | Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/reProtect/action | ReProtect Protected Item |
2363+
> | Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/switchprotection/action | Switch Protection Container |
22772364
> | Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/testFailover/action | Test Failover |
22782365
> | Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/testFailoverCleanup/action | Test Failover Cleanup |
22792366
> | Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/unplannedFailover/action | Failover |

0 commit comments

Comments
 (0)