Skip to content

Commit 455f072

Browse files
Merge pull request #263569 from rolyon/rolyon-rbac-roles-jan2024
[Azure RBAC] Update roles for January
2 parents e94c47c + d3816c6 commit 455f072

File tree

1 file changed

+13
-9
lines changed

1 file changed

+13
-9
lines changed

articles/role-based-access-control/built-in-roles.md

Lines changed: 13 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ ms.workload: identity
88
author: rolyon
99
manager: amycolannino
1010
ms.author: rolyon
11-
ms.date: 12/21/2023
11+
ms.date: 01/18/2024
1212
ms.custom: generated
1313
---
1414

@@ -909,7 +909,7 @@ View Virtual Machines in the portal and login as administrator
909909
> | [Microsoft.Network](resource-provider-operations.md#microsoftnetwork)/networkInterfaces/read | Gets a network interface definition. |
910910
> | [Microsoft.Compute](resource-provider-operations.md#microsoftcompute)/virtualMachines/*/read | |
911911
> | [Microsoft.HybridCompute](resource-provider-operations.md#microsofthybridcompute)/machines/*/read | |
912-
> | [Microsoft.HybridConnectivity](resource-provider-operations.md#microsofthybridconnectivity)/endpoints/listCredentials/action | List the endpoint access credentials to the resource. |
912+
> | [Microsoft.HybridConnectivity](resource-provider-operations.md#microsofthybridconnectivity)/endpoints/listCredentials/action | Gets the endpoint access credentials to the resource. |
913913
> | **NotActions** | |
914914
> | *none* | |
915915
> | **DataActions** | |
@@ -1164,12 +1164,12 @@ View Virtual Machines in the portal and login as a regular user.
11641164
> | [Microsoft.Network](resource-provider-operations.md#microsoftnetwork)/networkInterfaces/read | Gets a network interface definition. |
11651165
> | [Microsoft.Compute](resource-provider-operations.md#microsoftcompute)/virtualMachines/*/read | |
11661166
> | [Microsoft.HybridCompute](resource-provider-operations.md#microsofthybridcompute)/machines/*/read | |
1167-
> | [Microsoft.HybridConnectivity](resource-provider-operations.md#microsofthybridconnectivity)/endpoints/listCredentials/action | List the endpoint access credentials to the resource. |
1167+
> | [Microsoft.HybridConnectivity](resource-provider-operations.md#microsofthybridconnectivity)/endpoints/listCredentials/action | Gets the endpoint access credentials to the resource. |
11681168
> | **NotActions** | |
11691169
> | *none* | |
11701170
> | **DataActions** | |
11711171
> | [Microsoft.Compute](resource-provider-operations.md#microsoftcompute)/virtualMachines/login/action | Log in to a virtual machine as a regular user |
1172-
> | [Microsoft.HybridCompute](resource-provider-operations.md#microsofthybridcompute)/machines/login/action | Log in to a Azure Arc machine as a regular user |
1172+
> | [Microsoft.HybridCompute](resource-provider-operations.md#microsofthybridcompute)/machines/login/action | Log in to an Azure Arc machine as a regular user |
11731173
> | **NotDataActions** | |
11741174
> | *none* | |
11751175

@@ -1228,9 +1228,9 @@ Let's you manage the OS of your resource via Windows Admin Center as an administ
12281228
> | [Microsoft.Network](resource-provider-operations.md#microsoftnetwork)/networkWatchers/securityGroupView/action | View the configured and effective network security group rules applied on a VM. |
12291229
> | [Microsoft.Network](resource-provider-operations.md#microsoftnetwork)/networkSecurityGroups/securityRules/read | Gets a security rule definition |
12301230
> | [Microsoft.Network](resource-provider-operations.md#microsoftnetwork)/networkSecurityGroups/securityRules/write | Creates a security rule or updates an existing security rule |
1231-
> | [Microsoft.HybridConnectivity](resource-provider-operations.md#microsofthybridconnectivity)/endpoints/write | Create or update the endpoint to the target resource. |
1232-
> | [Microsoft.HybridConnectivity](resource-provider-operations.md#microsofthybridconnectivity)/endpoints/read | Get or list of endpoints to the target resource. |
1233-
> | [Microsoft.HybridConnectivity](resource-provider-operations.md#microsofthybridconnectivity)/endpoints/listManagedProxyDetails/action | Get managed proxy details for the resource. |
1231+
> | [Microsoft.HybridConnectivity](resource-provider-operations.md#microsofthybridconnectivity)/endpoints/write | Update the endpoint to the target resource. |
1232+
> | [Microsoft.HybridConnectivity](resource-provider-operations.md#microsofthybridconnectivity)/endpoints/read | Gets the endpoint to the resource. |
1233+
> | [Microsoft.HybridConnectivity](resource-provider-operations.md#microsofthybridconnectivity)/endpoints/listManagedProxyDetails/action | Fetches the managed proxy details |
12341234
> | [Microsoft.Compute](resource-provider-operations.md#microsoftcompute)/virtualMachines/read | Get the properties of a virtual machine |
12351235
> | [Microsoft.Compute](resource-provider-operations.md#microsoftcompute)/virtualMachines/patchAssessmentResults/latest/read | Retrieves the summary of the latest patch assessment operation |
12361236
> | [Microsoft.Compute](resource-provider-operations.md#microsoftcompute)/virtualMachines/patchAssessmentResults/latest/softwarePatches/read | Retrieves list of patches assessed during the last patch assessment operation |
@@ -6574,6 +6574,7 @@ Lets you manage Azure Cosmos DB accounts, but not access data in them. Prevents
65746574
> | [Microsoft.Support](resource-provider-operations.md#microsoftsupport)/* | Create and update a support ticket |
65756575
> | [Microsoft.Network](resource-provider-operations.md#microsoftnetwork)/virtualNetworks/subnets/joinViaServiceEndpoint/action | Joins resource such as storage account or SQL database to a subnet. Not alertable. |
65766576
> | **NotActions** | |
6577+
> | [Microsoft.DocumentDB](resource-provider-operations.md#microsoftdocumentdb)/databaseAccounts/dataTransferJobs/* | |
65776578
> | [Microsoft.DocumentDB](resource-provider-operations.md#microsoftdocumentdb)/databaseAccounts/readonlyKeys/* | |
65786579
> | [Microsoft.DocumentDB](resource-provider-operations.md#microsoftdocumentdb)/databaseAccounts/regenerateKey/* | |
65796580
> | [Microsoft.DocumentDB](resource-provider-operations.md#microsoftdocumentdb)/databaseAccounts/listKeys/* | |
@@ -6612,6 +6613,7 @@ Lets you manage Azure Cosmos DB accounts, but not access data in them. Prevents
66126613
"Microsoft.Network/virtualNetworks/subnets/joinViaServiceEndpoint/action"
66136614
],
66146615
"notActions": [
6616+
"Microsoft.DocumentDB/databaseAccounts/dataTransferJobs/*",
66156617
"Microsoft.DocumentDB/databaseAccounts/readonlyKeys/*",
66166618
"Microsoft.DocumentDB/databaseAccounts/regenerateKey/*",
66176619
"Microsoft.DocumentDB/databaseAccounts/listKeys/*",
@@ -13895,7 +13897,6 @@ Can read all monitoring data and edit monitoring settings. See also [Get started
1389513897
> | [Microsoft.OperationalInsights](resource-provider-operations.md#microsoftoperationalinsights)/workspaces/sharedKeys/action | Retrieves the shared keys for the workspace. These keys are used to connect Microsoft Operational Insights agents to the workspace. |
1389613898
> | [Microsoft.OperationalInsights](resource-provider-operations.md#microsoftoperationalinsights)/workspaces/storageinsightconfigs/* | Read/write/delete log analytics storage insight configurations. |
1389713899
> | [Microsoft.Support](resource-provider-operations.md#microsoftsupport)/* | Create and update a support ticket |
13898-
> | Microsoft.WorkloadMonitor/monitors/* | Get information about guest VM health monitors. |
1389913900
> | [Microsoft.AlertsManagement](resource-provider-operations.md#microsoftalertsmanagement)/smartDetectorAlertRules/* | |
1390013901
> | [Microsoft.AlertsManagement](resource-provider-operations.md#microsoftalertsmanagement)/actionRules/* | |
1390113902
> | [Microsoft.AlertsManagement](resource-provider-operations.md#microsoftalertsmanagement)/smartGroups/* | |
@@ -13951,7 +13952,6 @@ Can read all monitoring data and edit monitoring settings. See also [Get started
1395113952
"Microsoft.OperationalInsights/workspaces/sharedKeys/action",
1395213953
"Microsoft.OperationalInsights/workspaces/storageinsightconfigs/*",
1395313954
"Microsoft.Support/*",
13954-
"Microsoft.WorkloadMonitor/monitors/*",
1395513955
"Microsoft.AlertsManagement/smartDetectorAlertRules/*",
1395613956
"Microsoft.AlertsManagement/actionRules/*",
1395713957
"Microsoft.AlertsManagement/smartGroups/*",
@@ -17160,6 +17160,8 @@ Read-only role for Digital Twins data-plane properties
1716017160
> | [Microsoft.DigitalTwins](resource-provider-operations.md#microsoftdigitaltwins)/digitaltwins/relationships/read | Read any Digital Twin Relationship |
1716117161
> | [Microsoft.DigitalTwins](resource-provider-operations.md#microsoftdigitaltwins)/eventroutes/read | Read any Event Route |
1716217162
> | [Microsoft.DigitalTwins](resource-provider-operations.md#microsoftdigitaltwins)/jobs/import/read | Read any Bulk Import Job |
17163+
> | [Microsoft.DigitalTwins](resource-provider-operations.md#microsoftdigitaltwins)/jobs/imports/read | Read any Bulk Import Job |
17164+
> | [Microsoft.DigitalTwins](resource-provider-operations.md#microsoftdigitaltwins)/jobs/deletions/read | Read any Bulk Delete Job |
1716317165
> | [Microsoft.DigitalTwins](resource-provider-operations.md#microsoftdigitaltwins)/models/read | Read any Model |
1716417166
> | [Microsoft.DigitalTwins](resource-provider-operations.md#microsoftdigitaltwins)/query/action | Query any Digital Twins Graph |
1716517167
> | **NotDataActions** | |
@@ -17182,6 +17184,8 @@ Read-only role for Digital Twins data-plane properties
1718217184
"Microsoft.DigitalTwins/digitaltwins/relationships/read",
1718317185
"Microsoft.DigitalTwins/eventroutes/read",
1718417186
"Microsoft.DigitalTwins/jobs/import/read",
17187+
"Microsoft.DigitalTwins/jobs/imports/read",
17188+
"Microsoft.DigitalTwins/jobs/deletions/read",
1718517189
"Microsoft.DigitalTwins/models/read",
1718617190
"Microsoft.DigitalTwins/query/action"
1718717191
],

0 commit comments

Comments
 (0)