Skip to content

Commit 2812a5a

Browse files
authored
Merge pull request #97757 from rolyon/rolyon-rbac-roles-dec
[Azure RBAC] Updates to roles and operations for Dec
2 parents 35add7b + 73c1856 commit 2812a5a

File tree

2 files changed

+558
-59
lines changed

2 files changed

+558
-59
lines changed

articles/role-based-access-control/built-in-roles.md

Lines changed: 29 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ ms.devlang:
1212
ms.topic: reference
1313
ms.tgt_pltfrm:
1414
ms.workload: identity
15-
ms.date: 10/28/2019
15+
ms.date: 12/02/2019
1616
ms.author: rolyon
1717
ms.reviewer: bagovind
1818

@@ -119,9 +119,10 @@ The following table provides a brief description of each built-in role. Click th
119119
> | [Monitoring Reader](#monitoring-reader) | Can read all monitoring data (metrics, logs, etc.). See also [Get started with roles, permissions, and security with Azure Monitor](../azure-monitor/platform/roles-permissions-security.md#built-in-monitoring-roles). | 43d0d8ad-25c7-4714-9337-8ba259a9fe05 |
120120
> | [Network Contributor](#network-contributor) | Lets you manage networks, but not access to them. | 4d97b98b-1d4f-4787-a291-c67834d212e7 |
121121
> | [New Relic APM Account Contributor](#new-relic-apm-account-contributor) | Lets you manage New Relic Application Performance Management accounts and applications, but not access to them. | 5d28c62d-5b37-4476-8438-e587778df237 |
122+
> | [Policy Insights Data Writer (Preview)](#policy-insights-data-writer-preview) | Allows read access to resource policies and write access to resource component policy events. | 66bb4e9e-b016-4a94-8249-4c0511c2be84 |
122123
> | [Reader and Data Access](#reader-and-data-access) | Lets you view everything but will not let you delete or create a storage account or contained resource. It will also allow read/write access to all data contained in a storage account via access to storage account keys. | c12c1c16-33a1-487b-954d-41c89c60f349 |
123124
> | [Redis Cache Contributor](#redis-cache-contributor) | Lets you manage Redis caches, but not access to them. | e0f68234-74aa-48ed-b826-c38b57376e17 |
124-
> | [Resource Policy Contributor (Preview)](#resource-policy-contributor-preview) | (Preview) Backfilled users from EA, with rights to create/modify resource policy, create support ticket and read resources/hierarchy. | 36243c78-bf99-498c-9df9-86d9f8d28608 |
125+
> | [Resource Policy Contributor](#resource-policy-contributor) | Users with rights to create/modify resource policy, create support ticket and read resources/hierarchy. | 36243c78-bf99-498c-9df9-86d9f8d28608 |
125126
> | [Scheduler Job Collections Contributor](#scheduler-job-collections-contributor) | Lets you manage Scheduler job collections, but not access to them. | 188a0f2f-5c9e-469b-ae67-2aa5ce574b94 |
126127
> | [Search Service Contributor](#search-service-contributor) | Lets you manage Search services, but not access to them. | 7ca78c08-252a-4471-8644-bb5ff32d4ba0 |
127128
> | [Security Admin](#security-admin) | In Security Center only: Can view security policies, view security states, edit security policies, view alerts and recommendations, dismiss alerts and recommendations | fb1c8493-542b-48eb-b624-b4c8fea62acd |
@@ -662,6 +663,7 @@ The following table provides a brief description of each built-in role. Click th
662663
> | Microsoft.OperationalInsights/workspaces/savedSearches/* | |
663664
> | Microsoft.OperationsManagement/solutions/read | Get exiting OMS solution |
664665
> | Microsoft.OperationalInsights/workspaces/query/read | Run queries over the data in the workspace |
666+
> | Microsoft.OperationalInsights/workspaces/query/*/read | |
665667
> | Microsoft.OperationalInsights/workspaces/dataSources/read | Get datasources under a workspace. |
666668
> | Microsoft.Insights/workbooks/* | |
667669
> | Microsoft.Authorization/*/read | Read roles and role assignments |
@@ -689,6 +691,7 @@ The following table provides a brief description of each built-in role. Click th
689691
> | Microsoft.OperationalInsights/workspaces/savedSearches/read | Gets a saved search query |
690692
> | Microsoft.OperationsManagement/solutions/read | Get exiting OMS solution |
691693
> | Microsoft.OperationalInsights/workspaces/query/read | Run queries over the data in the workspace |
694+
> | Microsoft.OperationalInsights/workspaces/query/*/read | |
692695
> | Microsoft.OperationalInsights/workspaces/dataSources/read | Get datasources under a workspace. |
693696
> | Microsoft.Insights/workbooks/read | Read a workbook |
694697
> | Microsoft.Authorization/*/read | Read roles and role assignments |
@@ -718,6 +721,7 @@ The following table provides a brief description of each built-in role. Click th
718721
> | Microsoft.OperationalInsights/workspaces/savedSearches/read | Gets a saved search query |
719722
> | Microsoft.OperationsManagement/solutions/read | Get exiting OMS solution |
720723
> | Microsoft.OperationalInsights/workspaces/query/read | Run queries over the data in the workspace |
724+
> | Microsoft.OperationalInsights/workspaces/query/*/read | |
721725
> | Microsoft.OperationalInsights/workspaces/dataSources/read | Get datasources under a workspace. |
722726
> | Microsoft.Insights/workbooks/read | Read a workbook |
723727
> | Microsoft.Authorization/*/read | Read roles and role assignments |
@@ -1357,6 +1361,7 @@ The following table provides a brief description of each built-in role. Click th
13571361
> | Microsoft.Resources/deployments/* | Create and manage resource group deployments |
13581362
> | Microsoft.Resources/subscriptions/resourceGroups/read | Gets or lists resource groups. |
13591363
> | Microsoft.Support/* | Create and manage support tickets |
1364+
> | Microsoft.Network/virtualNetworks/subnets/joinViaServiceEndpoint/action | Joins resource such as storage account or SQL database to a subnet. Not alertable. |
13601365
> | **NotActions** | |
13611366
> | Microsoft.DocumentDB/databaseAccounts/readonlyKeys/* | |
13621367
> | Microsoft.DocumentDB/databaseAccounts/regenerateKey/* | |
@@ -1627,6 +1632,7 @@ The following table provides a brief description of each built-in role. Click th
16271632
> | Microsoft.Resources/deployments/* | Create and manage resource group deployments |
16281633
> | Microsoft.Resources/subscriptions/resourceGroups/read | Gets or lists resource groups. |
16291634
> | Microsoft.Support/* | Create and manage support tickets |
1635+
> | Microsoft.Network/virtualNetworks/subnets/joinViaServiceEndpoint/action | Joins resource such as storage account or SQL database to a subnet. Not alertable. |
16301636
> | **NotActions** | |
16311637
> | *none* | |
16321638
> | **DataActions** | |
@@ -2135,6 +2141,24 @@ The following table provides a brief description of each built-in role. Click th
21352141
> | **NotDataActions** | |
21362142
> | *none* | |
21372143
2144+
## Policy Insights Data Writer (Preview)
2145+
> [!div class="mx-tableFixed"]
2146+
> | | |
2147+
> | --- | --- |
2148+
> | **Description** | Allows read access to resource policies and write access to resource component policy events. |
2149+
> | **Id** | 66bb4e9e-b016-4a94-8249-4c0511c2be84 |
2150+
> | **Actions** | |
2151+
> | Microsoft.Authorization/policyassignments/read | Get information about a policy assignment. |
2152+
> | Microsoft.Authorization/policydefinitions/read | Get information about a policy definition. |
2153+
> | Microsoft.Authorization/policysetdefinitions/read | Get information about a policy set definition. |
2154+
> | **NotActions** | |
2155+
> | *none* | |
2156+
> | **DataActions** | |
2157+
> | Microsoft.PolicyInsights/checkDataPolicyCompliance/action | Check the compliance status of a given component against data policies. |
2158+
> | Microsoft.PolicyInsights/policyEvents/logDataEvents/action | Log the resource component policy events. |
2159+
> | **NotDataActions** | |
2160+
> | *none* | |
2161+
21382162
## Reader and Data Access
21392163
> [!div class="mx-tableFixed"]
21402164
> | | |
@@ -2173,11 +2197,11 @@ The following table provides a brief description of each built-in role. Click th
21732197
> | **NotDataActions** | |
21742198
> | *none* | |
21752199
2176-
## Resource Policy Contributor (Preview)
2200+
## Resource Policy Contributor
21772201
> [!div class="mx-tableFixed"]
21782202
> | | |
21792203
> | --- | --- |
2180-
> | **Description** | (Preview) Backfilled users from EA, with rights to create/modify resource policy, create support ticket and read resources/hierarchy. |
2204+
> | **Description** | Users with rights to create/modify resource policy, create support ticket and read resources/hierarchy. |
21812205
> | **Id** | 36243c78-bf99-498c-9df9-86d9f8d28608 |
21822206
> | **Actions** | |
21832207
> | */read | Read resources of all types, except secrets. |
@@ -2339,6 +2363,7 @@ The following table provides a brief description of each built-in role. Click th
23392363
> | Microsoft.Resources/deployments/* | Create and manage resource group deployments |
23402364
> | Microsoft.Resources/subscriptions/resourceGroups/read | Gets or lists resource groups. |
23412365
> | Microsoft.Storage/storageAccounts/read | Returns the list of storage accounts or gets the properties for the specified storage account. |
2366+
> | Microsoft.RecoveryServices/vaults/replicationOperationStatus/read | Read any Vault Replication Operation Status |
23422367
> | Microsoft.Support/* | Create and manage support tickets |
23432368
> | **NotActions** | |
23442369
> | *none* | |

0 commit comments

Comments
 (0)