Skip to content

Commit 55ca4c8

Browse files
committed
Updates to roles and operations
1 parent 650e12c commit 55ca4c8

File tree

2 files changed

+227
-45
lines changed

2 files changed

+227
-45
lines changed

articles/role-based-access-control/built-in-roles.md

Lines changed: 65 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ ms.devlang:
1212
ms.topic: reference
1313
ms.tgt_pltfrm:
1414
ms.workload: identity
15-
ms.date: 02/13/2020
15+
ms.date: 02/18/2020
1616
ms.author: rolyon
1717
ms.reviewer: bagovind
1818

@@ -130,6 +130,7 @@ The following table provides a brief description of each built-in role. Click th
130130
> | [Scheduler Job Collections Contributor](#scheduler-job-collections-contributor) | Lets you manage Scheduler job collections, but not access to them. | 188a0f2f-5c9e-469b-ae67-2aa5ce574b94 |
131131
> | [Search Service Contributor](#search-service-contributor) | Lets you manage Search services, but not access to them. | 7ca78c08-252a-4471-8644-bb5ff32d4ba0 |
132132
> | [Security Admin](#security-admin) | In Security Center only: Can view security policies, view security states, edit security policies, view alerts and recommendations, dismiss alerts and recommendations | fb1c8493-542b-48eb-b624-b4c8fea62acd |
133+
> | [Security Assessment Contributor](#security-assessment-contributor) | Lets you push assessments to Security Center | 612c2aa1-cb24-443b-ac28-3ab7272de6f5 |
133134
> | [Security Manager (Legacy)](#security-manager-legacy) | This is a legacy role. Please use Security Administrator instead | e3d13bf0-dd5a-482e-ba6b-9b8433878d10 |
134135
> | [Security Reader](#security-reader) | In Security Center only: Can view recommendations and alerts, view security policies, view security states, but cannot make changes | 39bc4728-0917-49c7-9d2c-d95423bc2eb4 |
135136
> | [Site Recovery Contributor](#site-recovery-contributor) | Lets you manage Site Recovery service except vault creation and role assignment | 6670b86e-a3f7-4917-ac9b-5d6ab1be4567 |
@@ -163,6 +164,8 @@ The following table provides a brief description of each built-in role. Click th
163164
> | [Virtual Machine User Login](#virtual-machine-user-login) | View Virtual Machines in the portal and login as a regular user. | fb879df8-f326-4884-b1cf-06f3ad86be52 |
164165
> | [Web Plan Contributor](#web-plan-contributor) | Lets you manage the web plans for websites, but not access to them. | 2cc479cb-7b4d-49a8-b449-8c00fd0f0a4b |
165166
> | [Website Contributor](#website-contributor) | Lets you manage websites (not web plans), but not access to them. | de139f84-1756-47ae-9be6-808fbbe84772 |
167+
> | [Workbook Contributor](#workbook-contributor) | Can save shared workbooks. | e8ddcd69-c73f-4f9f-9844-4100522f16ad |
168+
> | [Workbook Reader](#workbook-reader) | Can read workbooks. | b279062a-9be3-42a0-92ae-8b3cf002ec4d |
166169
167170

168171
## Owner
@@ -342,7 +345,7 @@ The following table provides a brief description of each built-in role. Click th
342345
> | Microsoft.ApiManagement/service/restore/action | Restore API Management Service from the specified container in a user provided storage account |
343346
> | Microsoft.ApiManagement/service/updatecertificate/action | Upload SSL certificate for an API Management Service |
344347
> | Microsoft.ApiManagement/service/updatehostname/action | Setup, update or remove custom domain names for an API Management Service |
345-
> | Microsoft.ApiManagement/service/write | Create a new instance of API Management Service |
348+
> | Microsoft.ApiManagement/service/write | Create or Update API Management Service instance |
346349
> | Microsoft.Authorization/*/read | Read authorization |
347350
> | Microsoft.Insights/alertRules/* | Create and manage alert rules |
348351
> | Microsoft.ResourceHealth/availabilityStatuses/read | Gets the availability statuses for all resources in the specified scope |
@@ -605,7 +608,7 @@ The following table provides a brief description of each built-in role. Click th
605608
> | **Id** | b64e21ea-ac4e-4cdf-9dc9-5b892992bee7 |
606609
> | **Actions** | |
607610
> | Microsoft.HybridCompute/machines/read | Read any Azure Arc machines |
608-
> | Microsoft.HybridCompute/machines/write | Write a Azure Arc machines |
611+
> | Microsoft.HybridCompute/machines/write | Writes an Azure Arc machines |
609612
> | Microsoft.GuestConfiguration/guestConfigurationAssignments/read | Get guest configuration assignment. |
610613
> | **NotActions** | |
611614
> | *none* | |
@@ -622,9 +625,9 @@ The following table provides a brief description of each built-in role. Click th
622625
> | **Id** | cd570a14-e51a-42ad-bac8-bafd67325302 |
623626
> | **Actions** | |
624627
> | Microsoft.HybridCompute/machines/read | Read any Azure Arc machines |
625-
> | Microsoft.HybridCompute/machines/write | Write a Azure Arc machines |
626-
> | Microsoft.HybridCompute/machines/delete | Delete a Azure Arc machines |
627-
> | Microsoft.HybridCompute/machines/reconnect/action | Reconnect a Azure Arc machines |
628+
> | Microsoft.HybridCompute/machines/write | Writes an Azure Arc machines |
629+
> | Microsoft.HybridCompute/machines/delete | Deletes an Azure Arc machines |
630+
> | Microsoft.HybridCompute/machines/reconnect/action | Reconnects an Azure Arc machines |
628631
> | Microsoft.HybridCompute/*/read | |
629632
> | **NotActions** | |
630633
> | *none* | |
@@ -686,6 +689,7 @@ The following table provides a brief description of each built-in role. Click th
686689
> | **Id** | 0ab0b1a8-8aac-4efd-b8c2-3ee1fb270be8 |
687690
> | **Actions** | |
688691
> | Microsoft.ContainerService/managedClusters/listClusterAdminCredential/action | List the clusterAdmin credential of a managed cluster |
692+
> | Microsoft.ContainerService/managedClusters/accessProfiles/listCredential/action | Get a managed cluster access profile by role name using list credential |
689693
> | **NotActions** | |
690694
> | *none* | |
691695
> | **DataActions** | |
@@ -1536,6 +1540,8 @@ The following table provides a brief description of each built-in role. Click th
15361540
> | Microsoft.Databox/jobs/listsecrets/action | |
15371541
> | Microsoft.Databox/jobs/listcredentials/action | Lists the unencrypted credentials related to the order. |
15381542
> | Microsoft.Databox/locations/availableSkus/action | This method returns the list of available skus. |
1543+
> | Microsoft.Databox/locations/validateInputs/action | This method does all type of validations. |
1544+
> | Microsoft.Databox/locations/regionConfiguration/action | This method returns the configurations for the region. |
15391545
> | Microsoft.Databox/locations/validateAddress/action | Validates the shipping address and provides alternate addresses if any. |
15401546
> | Microsoft.ResourceHealth/availabilityStatuses/read | Gets the availability statuses for all resources in the specified scope |
15411547
> | Microsoft.Support/* | Create and manage support tickets |
@@ -1561,6 +1567,7 @@ The following table provides a brief description of each built-in role. Click th
15611567
> | Microsoft.Resources/deployments/* | Create and manage resource group deployments |
15621568
> | Microsoft.Resources/subscriptions/resourceGroups/read | Gets or lists resource groups. |
15631569
> | Microsoft.Support/* | Create and manage support tickets |
1570+
> | Microsoft.EventGrid/eventSubscriptions/write | Create or update an eventSubscription |
15641571
> | **NotActions** | |
15651572
> | *none* | |
15661573
> | **DataActions** | |
@@ -1847,6 +1854,8 @@ The following table provides a brief description of each built-in role. Click th
18471854
> | Microsoft.LabServices/labAccounts/createLab/action | Create a lab in a lab account. |
18481855
> | Microsoft.LabServices/labAccounts/sizes/getRegionalAvailability/action | |
18491856
> | Microsoft.LabServices/labAccounts/getRegionalAvailability/action | Get regional availability information for each size category configured under a lab account |
1857+
> | Microsoft.LabServices/labAccounts/getPricingAndAvailability/action | Get the pricing and availability of combinations of sizes, geographies, and operating systems for the lab account. |
1858+
> | Microsoft.LabServices/labAccounts/getRestrictionsAndUsage/action | Get core restrictions and usage for this subscription |
18501859
> | Microsoft.Resources/subscriptions/resourceGroups/read | Gets or lists resource groups. |
18511860
> | Microsoft.Support/* | Create and manage support tickets |
18521861
> | **NotActions** | |
@@ -2354,6 +2363,21 @@ The following table provides a brief description of each built-in role. Click th
23542363
> | **NotDataActions** | |
23552364
> | *none* | |
23562365
2366+
## Security Assessment Contributor
2367+
> [!div class="mx-tableFixed"]
2368+
> | | |
2369+
> | --- | --- |
2370+
> | **Description** | Lets you push assessments to Security Center |
2371+
> | **Id** | 612c2aa1-cb24-443b-ac28-3ab7272de6f5 |
2372+
> | **Actions** | |
2373+
> | Microsoft.Security/assessments/write | Create or update security assessments on your subscription |
2374+
> | **NotActions** | |
2375+
> | *none* | |
2376+
> | **DataActions** | |
2377+
> | *none* | |
2378+
> | **NotDataActions** | |
2379+
> | *none* | |
2380+
23572381
## Security Manager (Legacy)
23582382
> [!div class="mx-tableFixed"]
23592383
> | | |
@@ -3110,6 +3134,9 @@ The following table provides a brief description of each built-in role. Click th
31103134
> | Microsoft.Compute/locations/* | Create and manage compute locations |
31113135
> | Microsoft.Compute/virtualMachines/* | Create and manage virtual machines |
31123136
> | Microsoft.Compute/virtualMachineScaleSets/* | Create and manage virtual machine scale sets |
3137+
> | Microsoft.Compute/disks/write | Creates a new Disk or updates an existing one |
3138+
> | Microsoft.Compute/disks/read | Get the properties of a Disk |
3139+
> | Microsoft.Compute/disks/delete | Deletes the Disk |
31133140
> | Microsoft.DevTestLab/schedules/* | |
31143141
> | Microsoft.Insights/alertRules/* | Create and manage Insights alert rules |
31153142
> | Microsoft.Network/applicationGateways/backendAddressPools/join/action | Joins an application gateway backend address pool. Not Alertable. |
@@ -3217,6 +3244,38 @@ The following table provides a brief description of each built-in role. Click th
32173244
> | **NotDataActions** | |
32183245
> | *none* | |
32193246
3247+
## Workbook Contributor
3248+
> [!div class="mx-tableFixed"]
3249+
> | | |
3250+
> | --- | --- |
3251+
> | **Description** | Can save shared workbooks. |
3252+
> | **Id** | e8ddcd69-c73f-4f9f-9844-4100522f16ad |
3253+
> | **Actions** | |
3254+
> | Microsoft.Insights/workbooks/write | Create or update a workbook |
3255+
> | Microsoft.Insights/workbooks/delete | Delete a workbook |
3256+
> | Microsoft.Insights/workbooks/read | Read a workbook |
3257+
> | **NotActions** | |
3258+
> | *none* | |
3259+
> | **DataActions** | |
3260+
> | *none* | |
3261+
> | **NotDataActions** | |
3262+
> | *none* | |
3263+
3264+
## Workbook Reader
3265+
> [!div class="mx-tableFixed"]
3266+
> | | |
3267+
> | --- | --- |
3268+
> | **Description** | Can read workbooks. |
3269+
> | **Id** | b279062a-9be3-42a0-92ae-8b3cf002ec4d |
3270+
> | **Actions** | |
3271+
> | microsoft.insights/workbooks/read | Read a workbook |
3272+
> | **NotActions** | |
3273+
> | *none* | |
3274+
> | **DataActions** | |
3275+
> | *none* | |
3276+
> | **NotDataActions** | |
3277+
> | *none* | |
3278+
32203279
## Next steps
32213280

32223281
- [Match resource provider to service](../azure-resource-manager/management/azure-services-resource-providers.md)

0 commit comments

Comments
 (0)