You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/role-based-access-control/built-in-roles.md
+65-6Lines changed: 65 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,7 +12,7 @@ ms.devlang:
12
12
ms.topic: reference
13
13
ms.tgt_pltfrm:
14
14
ms.workload: identity
15
-
ms.date: 02/13/2020
15
+
ms.date: 02/18/2020
16
16
ms.author: rolyon
17
17
ms.reviewer: bagovind
18
18
@@ -130,6 +130,7 @@ The following table provides a brief description of each built-in role. Click th
130
130
> |[Scheduler Job Collections Contributor](#scheduler-job-collections-contributor)| Lets you manage Scheduler job collections, but not access to them. | 188a0f2f-5c9e-469b-ae67-2aa5ce574b94 |
131
131
> |[Search Service Contributor](#search-service-contributor)| Lets you manage Search services, but not access to them. | 7ca78c08-252a-4471-8644-bb5ff32d4ba0 |
132
132
> |[Security Admin](#security-admin)| In Security Center only: Can view security policies, view security states, edit security policies, view alerts and recommendations, dismiss alerts and recommendations | fb1c8493-542b-48eb-b624-b4c8fea62acd |
133
+
> |[Security Assessment Contributor](#security-assessment-contributor)| Lets you push assessments to Security Center | 612c2aa1-cb24-443b-ac28-3ab7272de6f5 |
133
134
> |[Security Manager (Legacy)](#security-manager-legacy)| This is a legacy role. Please use Security Administrator instead | e3d13bf0-dd5a-482e-ba6b-9b8433878d10 |
134
135
> |[Security Reader](#security-reader)| In Security Center only: Can view recommendations and alerts, view security policies, view security states, but cannot make changes | 39bc4728-0917-49c7-9d2c-d95423bc2eb4 |
135
136
> |[Site Recovery Contributor](#site-recovery-contributor)| Lets you manage Site Recovery service except vault creation and role assignment | 6670b86e-a3f7-4917-ac9b-5d6ab1be4567 |
@@ -163,6 +164,8 @@ The following table provides a brief description of each built-in role. Click th
163
164
> |[Virtual Machine User Login](#virtual-machine-user-login)| View Virtual Machines in the portal and login as a regular user. | fb879df8-f326-4884-b1cf-06f3ad86be52 |
164
165
> |[Web Plan Contributor](#web-plan-contributor)| Lets you manage the web plans for websites, but not access to them. | 2cc479cb-7b4d-49a8-b449-8c00fd0f0a4b |
165
166
> |[Website Contributor](#website-contributor)| Lets you manage websites (not web plans), but not access to them. | de139f84-1756-47ae-9be6-808fbbe84772 |
167
+
> |[Workbook Contributor](#workbook-contributor)| Can save shared workbooks. | e8ddcd69-c73f-4f9f-9844-4100522f16ad |
168
+
> |[Workbook Reader](#workbook-reader)| Can read workbooks. | b279062a-9be3-42a0-92ae-8b3cf002ec4d |
166
169
167
170
168
171
## Owner
@@ -342,7 +345,7 @@ The following table provides a brief description of each built-in role. Click th
342
345
> | Microsoft.ApiManagement/service/restore/action | Restore API Management Service from the specified container in a user provided storage account |
343
346
> | Microsoft.ApiManagement/service/updatecertificate/action | Upload SSL certificate for an API Management Service |
344
347
> | Microsoft.ApiManagement/service/updatehostname/action | Setup, update or remove custom domain names for an API Management Service |
345
-
> | Microsoft.ApiManagement/service/write | Create a new instance of API Management Service |
348
+
> | Microsoft.ApiManagement/service/write | Create or Update API Management Service instance|
> | Microsoft.Insights/alertRules/*| Create and manage alert rules |
348
351
> | Microsoft.ResourceHealth/availabilityStatuses/read | Gets the availability statuses for all resources in the specified scope |
@@ -605,7 +608,7 @@ The following table provides a brief description of each built-in role. Click th
605
608
> |**Id**| b64e21ea-ac4e-4cdf-9dc9-5b892992bee7 |
606
609
> |**Actions**||
607
610
> | Microsoft.HybridCompute/machines/read | Read any Azure Arc machines |
608
-
> | Microsoft.HybridCompute/machines/write |Write a Azure Arc machines |
611
+
> | Microsoft.HybridCompute/machines/write |Writes an Azure Arc machines |
609
612
> | Microsoft.GuestConfiguration/guestConfigurationAssignments/read | Get guest configuration assignment. |
610
613
> |**NotActions**||
611
614
> |*none*||
@@ -622,9 +625,9 @@ The following table provides a brief description of each built-in role. Click th
622
625
> |**Id**| cd570a14-e51a-42ad-bac8-bafd67325302 |
623
626
> |**Actions**||
624
627
> | Microsoft.HybridCompute/machines/read | Read any Azure Arc machines |
625
-
> | Microsoft.HybridCompute/machines/write |Write a Azure Arc machines |
626
-
> | Microsoft.HybridCompute/machines/delete |Delete a Azure Arc machines |
627
-
> | Microsoft.HybridCompute/machines/reconnect/action |Reconnect a Azure Arc machines |
628
+
> | Microsoft.HybridCompute/machines/write |Writes an Azure Arc machines |
629
+
> | Microsoft.HybridCompute/machines/delete |Deletes an Azure Arc machines |
630
+
> | Microsoft.HybridCompute/machines/reconnect/action |Reconnects an Azure Arc machines |
628
631
> | Microsoft.HybridCompute/*/read ||
629
632
> |**NotActions**||
630
633
> |*none*||
@@ -686,6 +689,7 @@ The following table provides a brief description of each built-in role. Click th
686
689
> |**Id**| 0ab0b1a8-8aac-4efd-b8c2-3ee1fb270be8 |
687
690
> |**Actions**||
688
691
> | Microsoft.ContainerService/managedClusters/listClusterAdminCredential/action | List the clusterAdmin credential of a managed cluster |
692
+
> | Microsoft.ContainerService/managedClusters/accessProfiles/listCredential/action | Get a managed cluster access profile by role name using list credential |
689
693
> |**NotActions**||
690
694
> |*none*||
691
695
> |**DataActions**||
@@ -1536,6 +1540,8 @@ The following table provides a brief description of each built-in role. Click th
1536
1540
> | Microsoft.Databox/jobs/listsecrets/action ||
1537
1541
> | Microsoft.Databox/jobs/listcredentials/action | Lists the unencrypted credentials related to the order. |
1538
1542
> | Microsoft.Databox/locations/availableSkus/action | This method returns the list of available skus. |
1543
+
> | Microsoft.Databox/locations/validateInputs/action | This method does all type of validations. |
1544
+
> | Microsoft.Databox/locations/regionConfiguration/action | This method returns the configurations for the region. |
1539
1545
> | Microsoft.Databox/locations/validateAddress/action | Validates the shipping address and provides alternate addresses if any. |
1540
1546
> | Microsoft.ResourceHealth/availabilityStatuses/read | Gets the availability statuses for all resources in the specified scope |
1541
1547
> | Microsoft.Support/*| Create and manage support tickets |
@@ -1561,6 +1567,7 @@ The following table provides a brief description of each built-in role. Click th
1561
1567
> | Microsoft.Resources/deployments/*| Create and manage resource group deployments |
1562
1568
> | Microsoft.Resources/subscriptions/resourceGroups/read | Gets or lists resource groups. |
1563
1569
> | Microsoft.Support/*| Create and manage support tickets |
1570
+
> | Microsoft.EventGrid/eventSubscriptions/write | Create or update an eventSubscription |
1564
1571
> |**NotActions**||
1565
1572
> |*none*||
1566
1573
> |**DataActions**||
@@ -1847,6 +1854,8 @@ The following table provides a brief description of each built-in role. Click th
1847
1854
> | Microsoft.LabServices/labAccounts/createLab/action | Create a lab in a lab account. |
> | Microsoft.LabServices/labAccounts/getRegionalAvailability/action | Get regional availability information for each size category configured under a lab account |
1857
+
> | Microsoft.LabServices/labAccounts/getPricingAndAvailability/action | Get the pricing and availability of combinations of sizes, geographies, and operating systems for the lab account. |
1858
+
> | Microsoft.LabServices/labAccounts/getRestrictionsAndUsage/action | Get core restrictions and usage for this subscription |
1850
1859
> | Microsoft.Resources/subscriptions/resourceGroups/read | Gets or lists resource groups. |
1851
1860
> | Microsoft.Support/*| Create and manage support tickets |
1852
1861
> |**NotActions**||
@@ -2354,6 +2363,21 @@ The following table provides a brief description of each built-in role. Click th
2354
2363
> |**NotDataActions**||
2355
2364
> |*none*||
2356
2365
2366
+
## Security Assessment Contributor
2367
+
> [!div class="mx-tableFixed"]
2368
+
> |||
2369
+
> | --- | --- |
2370
+
> |**Description**| Lets you push assessments to Security Center |
2371
+
> |**Id**| 612c2aa1-cb24-443b-ac28-3ab7272de6f5 |
2372
+
> |**Actions**||
2373
+
> | Microsoft.Security/assessments/write | Create or update security assessments on your subscription |
2374
+
> |**NotActions**||
2375
+
> |*none*||
2376
+
> |**DataActions**||
2377
+
> |*none*||
2378
+
> |**NotDataActions**||
2379
+
> |*none*||
2380
+
2357
2381
## Security Manager (Legacy)
2358
2382
> [!div class="mx-tableFixed"]
2359
2383
> |||
@@ -3110,6 +3134,9 @@ The following table provides a brief description of each built-in role. Click th
3110
3134
> | Microsoft.Compute/locations/*| Create and manage compute locations |
3111
3135
> | Microsoft.Compute/virtualMachines/*| Create and manage virtual machines |
0 commit comments