Skip to content

Commit 6a27e20

Browse files
authored
Merge pull request #300373 from MicrosoftDocs/main
5/26/2025 PM Publish
2 parents bd26c99 + 8226806 commit 6a27e20

40 files changed

+246
-158
lines changed

articles/event-hubs/schema-registry-concepts.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -129,8 +129,8 @@ To access a schema registry programmatically, follow these steps:
129129
| ---- | ----------- |
130130
| Owner | Read, write, and delete schema registry groups and schemas |
131131
| Contributor | Read, write, and delete schema registry groups and schemas |
132-
| [Schema Registry Reader](../role-based-access-control/built-in-roles.md#schema-registry-reader-preview) | Read and list schema registry groups and schemas |
133-
| [Schema Registry Contributor](../role-based-access-control/built-in-roles.md#schema-registry-reader-preview) | Read, write, and delete schema registry groups and schemas |
132+
| [Schema Registry Reader](../role-based-access-control/built-in-roles/analytics.md#schema-registry-reader) | Read and list schema registry groups and schemas |
133+
| [Schema Registry Contributor](../role-based-access-control/built-in-roles/analytics.md#schema-registry-contributor) | Read, write, and delete schema registry groups and schemas |
134134

135135
To learn how to create and register an application by using the Azure portal, see [Register an application with Microsoft Entra ID](../active-directory/develop/quickstart-register-app.md). You need the client ID (application ID), the tenant ID, and the secret to use in the code.
136136

articles/role-based-access-control/built-in-roles.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.workload: identity
77
author: rolyon
88
manager: femila
99
ms.author: rolyon
10-
ms.date: 04/25/2025
10+
ms.date: 05/25/2025
1111
ms.custom: generated
1212
---
1313

@@ -271,8 +271,8 @@ The following table provides a brief description of each built-in role. Click th
271271
> | <a name='hdinsight-domain-services-contributor'></a>[HDInsight Domain Services Contributor](./built-in-roles/analytics.md#hdinsight-domain-services-contributor) | Can Read, Create, Modify and Delete Domain Services related operations needed for HDInsight Enterprise Security Package | 8d8d5a11-05d3-4bda-a417-a08778121c7c |
272272
> | <a name='hdinsight-on-aks-cluster-admin'></a>[HDInsight on AKS Cluster Admin](./built-in-roles/analytics.md#hdinsight-on-aks-cluster-admin) | Grants a user/group the ability to create, delete and manage clusters within a given cluster pool. Cluster Admin can also run workloads, monitor, and manage all user activity on these clusters. | fd036e6b-1266-47a0-b0bb-a05d04831731 |
273273
> | <a name='hdinsight-on-aks-cluster-pool-admin'></a>[HDInsight on AKS Cluster Pool Admin](./built-in-roles/analytics.md#hdinsight-on-aks-cluster-pool-admin) | Can read, create, modify and delete HDInsight on AKS cluster pools and create clusters | 7656b436-37d4-490a-a4ab-d39f838f0042 |
274-
> | <a name='schema-registry-contributor-preview'></a>[Schema Registry Contributor (Preview)](./built-in-roles/analytics.md#schema-registry-contributor-preview) | Read, write, and delete Schema Registry groups and schemas. | 5dffeca3-4936-4216-b2bc-10343a5abb25 |
275-
> | <a name='schema-registry-reader-preview'></a>[Schema Registry Reader (Preview)](./built-in-roles/analytics.md#schema-registry-reader-preview) | Read and list Schema Registry groups and schemas. | 2c56ea50-c6b3-40a6-83c0-9d98858bc7d2 |
274+
> | <a name='schema-registry-contributor'></a>[Schema Registry Contributor](./built-in-roles/analytics.md#schema-registry-contributor) | Read, write, and delete Schema Registry groups and schemas. | 5dffeca3-4936-4216-b2bc-10343a5abb25 |
275+
> | <a name='schema-registry-reader'></a>[Schema Registry Reader](./built-in-roles/analytics.md#schema-registry-reader) | Read and list Schema Registry groups and schemas. | 2c56ea50-c6b3-40a6-83c0-9d98858bc7d2 |
276276
> | <a name='stream-analytics-query-tester'></a>[Stream Analytics Query Tester](./built-in-roles/analytics.md#stream-analytics-query-tester) | Lets you perform query testing without creating a stream analytics job first | 1ec5b3c1-b17e-4e25-8312-2acb3c3c5abf |
277277
278278
## AI + machine learning

articles/role-based-access-control/built-in-roles/ai-machine-learning.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.workload: identity
77
author: rolyon
88
manager: femila
99
ms.author: rolyon
10-
ms.date: 04/25/2025
10+
ms.date: 05/25/2025
1111
ms.custom: generated
1212
---
1313

@@ -1753,6 +1753,7 @@ Read access to view files, models, deployments. The ability to create completion
17531753
> | [Microsoft.CognitiveServices](../permissions/ai-machine-learning.md#microsoftcognitiveservices)/accounts/OpenAI/deployments/embeddings/action | Return the embeddings for a given prompt. |
17541754
> | [Microsoft.CognitiveServices](../permissions/ai-machine-learning.md#microsoftcognitiveservices)/accounts/OpenAI/images/generations/action | Create image generations. |
17551755
> | [Microsoft.CognitiveServices](../permissions/ai-machine-learning.md#microsoftcognitiveservices)/accounts/OpenAI/video/generations/*/action | |
1756+
> | [Microsoft.CognitiveServices](../permissions/ai-machine-learning.md#microsoftcognitiveservices)/accounts/OpenAI/video/generations/*/delete | |
17561757
> | [Microsoft.CognitiveServices](../permissions/ai-machine-learning.md#microsoftcognitiveservices)/accounts/OpenAI/assistants/* | |
17571758
> | [Microsoft.CognitiveServices](../permissions/ai-machine-learning.md#microsoftcognitiveservices)/accounts/OpenAI/responses/* | |
17581759
> | **NotDataActions** | |
@@ -1788,6 +1789,7 @@ Read access to view files, models, deployments. The ability to create completion
17881789
"Microsoft.CognitiveServices/accounts/OpenAI/deployments/embeddings/action",
17891790
"Microsoft.CognitiveServices/accounts/OpenAI/images/generations/action",
17901791
"Microsoft.CognitiveServices/accounts/OpenAI/video/generations/*/action",
1792+
"Microsoft.CognitiveServices/accounts/OpenAI/video/generations/*/delete",
17911793
"Microsoft.CognitiveServices/accounts/OpenAI/assistants/*",
17921794
"Microsoft.CognitiveServices/accounts/OpenAI/responses/*"
17931795
],

articles/role-based-access-control/built-in-roles/analytics.md

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.workload: identity
77
author: rolyon
88
manager: femila
99
ms.author: rolyon
10-
ms.date: 04/25/2025
10+
ms.date: 05/25/2025
1111
ms.custom: generated
1212
---
1313

@@ -332,7 +332,7 @@ Grants a user/group the ability to create, delete and manage clusters within a g
332332
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/operations/read | Gets or lists deployment operations. |
333333
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/*/read | |
334334
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/read | Gets or lists deployments. |
335-
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/validate/action | Validates an deployment. |
335+
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/validate/action | Validates a deployment. |
336336
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/write | Creates or updates an deployment. |
337337
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/exportTemplate/action | Export template for a deployment |
338338
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/subscriptions/resourcegroups/deployments/operations/read | Gets or lists deployment operations. |
@@ -433,12 +433,12 @@ Can read, create, modify and delete HDInsight on AKS cluster pools and create cl
433433
> | [Microsoft.HDInsight](../permissions/analytics.md#microsofthdinsight)/clusterPools/upgradehistories/read | Read HDInsight on AKS Cluster Pool Upgrade Histories |
434434
> | [Microsoft.ResourceHealth](../permissions/management-and-governance.md#microsoftresourcehealth)/availabilityStatuses/read | Gets the availability statuses for all resources in the specified scope |
435435
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/operations/read | Gets or lists deployment operations. |
436-
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/validate/action | Validates an deployment. |
436+
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/validate/action | Validates a deployment. |
437437
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/*/read | |
438438
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/read | Gets or lists deployments. |
439439
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/write | Creates or updates an deployment. |
440440
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/exportTemplate/action | Export template for a deployment |
441-
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/validate/action | Validates an deployment. |
441+
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/validate/action | Validates a deployment. |
442442
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/subscriptions/resourcegroups/deployments/operations/read | Gets or lists deployment operations. |
443443
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/subscriptions/resourcegroups/deployments/read | Gets or lists deployments. |
444444
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/subscriptions/resourceGroups/read | Gets or lists resource groups. |
@@ -512,7 +512,7 @@ Can read, create, modify and delete HDInsight on AKS cluster pools and create cl
512512
}
513513
```
514514

515-
## Schema Registry Contributor (Preview)
515+
## Schema Registry Contributor
516516

517517
Read, write, and delete Schema Registry groups and schemas.
518518

@@ -547,13 +547,13 @@ Read, write, and delete Schema Registry groups and schemas.
547547
"notDataActions": []
548548
}
549549
],
550-
"roleName": "Schema Registry Contributor (Preview)",
550+
"roleName": "Schema Registry Contributor",
551551
"roleType": "BuiltInRole",
552552
"type": "Microsoft.Authorization/roleDefinitions"
553553
}
554554
```
555555

556-
## Schema Registry Reader (Preview)
556+
## Schema Registry Reader
557557

558558
Read and list Schema Registry groups and schemas.
559559

@@ -588,7 +588,7 @@ Read and list Schema Registry groups and schemas.
588588
"notDataActions": []
589589
}
590590
],
591-
"roleName": "Schema Registry Reader (Preview)",
591+
"roleName": "Schema Registry Reader",
592592
"roleType": "BuiltInRole",
593593
"type": "Microsoft.Authorization/roleDefinitions"
594594
}

articles/role-based-access-control/built-in-roles/compute.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.workload: identity
77
author: rolyon
88
manager: femila
99
ms.author: rolyon
10-
ms.date: 04/25/2025
10+
ms.date: 05/25/2025
1111
ms.custom: generated
1212
---
1313

@@ -38,7 +38,7 @@ Arc VMware VM Contributor has permissions to perform all VM actions.
3838
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/write | Creates or updates an deployment. |
3939
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/delete | Deletes a deployment. |
4040
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/cancel/action | Cancels a deployment. |
41-
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/validate/action | Validates an deployment. |
41+
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/validate/action | Validates a deployment. |
4242
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/whatIf/action | Predicts template deployment changes. |
4343
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/exportTemplate/action | Export template for a deployment |
4444
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/operations/read | Gets or lists deployment operations. |

articles/role-based-access-control/built-in-roles/containers.md

Lines changed: 11 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.workload: identity
77
author: rolyon
88
manager: femila
99
ms.author: rolyon
10-
ms.date: 04/25/2025
10+
ms.date: 05/25/2025
1111
ms.custom: generated
1212
---
1313

@@ -2629,6 +2629,7 @@ Install and upgrade the networking components on an OpenShift cluster.
26292629
> | [Microsoft.Network](../permissions/networking.md#microsoftnetwork)/virtualNetworks/read | Get the virtual network definition |
26302630
> | [Microsoft.Network](../permissions/networking.md#microsoftnetwork)/virtualNetworks/subnets/join/action | Joins a virtual network. Not Alertable. |
26312631
> | [Microsoft.Network](../permissions/networking.md#microsoftnetwork)/loadBalancers/backendAddressPools/join/action | Joins a load balancer backend address pool. Not Alertable. |
2632+
> | [Microsoft.Network](../permissions/networking.md#microsoftnetwork)/loadBalancers/backendAddressPools/read | Gets a load balancer backend address pool definition |
26322633
> | [Microsoft.Compute](../permissions/compute.md#microsoftcompute)/virtualMachines/read | Get the properties of a virtual machine |
26332634
> | **NotActions** | |
26342635
> | *none* | |
@@ -2653,6 +2654,7 @@ Install and upgrade the networking components on an OpenShift cluster.
26532654
"Microsoft.Network/virtualNetworks/read",
26542655
"Microsoft.Network/virtualNetworks/subnets/join/action",
26552656
"Microsoft.Network/loadBalancers/backendAddressPools/join/action",
2657+
"Microsoft.Network/loadBalancers/backendAddressPools/read",
26562658
"Microsoft.Compute/virtualMachines/read"
26572659
],
26582660
"notActions": [],
@@ -3183,7 +3185,9 @@ Provides the ability to import images into a registry through the registry impor
31833185
> | **NotActions** | |
31843186
> | *none* | |
31853187
> | **DataActions** | |
3186-
> | *none* | |
3188+
> | [Microsoft.ContainerRegistry](../permissions/containers.md#microsoftcontainerregistry)/registries/repositories/content/read | Pull or Get images from a container registry. |
3189+
> | [Microsoft.ContainerRegistry](../permissions/containers.md#microsoftcontainerregistry)/registries/repositories/metadata/read | Gets the metadata of a specific repository for a container registry |
3190+
> | [Microsoft.ContainerRegistry](../permissions/containers.md#microsoftcontainerregistry)/registries/catalog/read | List repositories in a container registry. |
31873191
> | **NotDataActions** | |
31883192
> | *none* | |
31893193
@@ -3203,7 +3207,11 @@ Provides the ability to import images into a registry through the registry impor
32033207
"Microsoft.ContainerRegistry/registries/pull/read"
32043208
],
32053209
"notActions": [],
3206-
"dataActions": [],
3210+
"dataActions": [
3211+
"Microsoft.ContainerRegistry/registries/repositories/content/read",
3212+
"Microsoft.ContainerRegistry/registries/repositories/metadata/read",
3213+
"Microsoft.ContainerRegistry/registries/catalog/read"
3214+
],
32073215
"notDataActions": []
32083216
}
32093217
],

articles/role-based-access-control/built-in-roles/databases.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.workload: identity
77
author: rolyon
88
manager: femila
99
ms.author: rolyon
10-
ms.date: 04/25/2025
10+
ms.date: 05/25/2025
1111
ms.custom: generated
1212
---
1313

articles/role-based-access-control/built-in-roles/devops.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.workload: identity
77
author: rolyon
88
manager: femila
99
ms.author: rolyon
10-
ms.date: 04/25/2025
10+
ms.date: 05/25/2025
1111
ms.custom: generated
1212
---
1313

articles/role-based-access-control/built-in-roles/general.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.workload: identity
77
author: rolyon
88
manager: femila
99
ms.author: rolyon
10-
ms.date: 04/25/2025
10+
ms.date: 05/25/2025
1111
ms.custom: generated
1212
---
1313

articles/role-based-access-control/built-in-roles/hybrid-multicloud.md

Lines changed: 13 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.workload: identity
77
author: rolyon
88
manager: femila
99
ms.author: rolyon
10-
ms.date: 04/25/2025
10+
ms.date: 05/25/2025
1111
ms.custom: generated
1212
---
1313

@@ -235,6 +235,11 @@ Grants full access to the cluster and its resources, including the ability to re
235235
> | [Microsoft.AzureStackHCI](../permissions/hybrid-multicloud.md#microsoftazurestackhci)/StorageContainers/Write | Creates/Updates storage containers resource |
236236
> | [Microsoft.AzureStackHCI](../permissions/hybrid-multicloud.md#microsoftazurestackhci)/StorageContainers/Read | Gets/Lists storage containers resource |
237237
> | [Microsoft.HybridContainerService](../permissions/hybrid-multicloud.md#microsofthybridcontainerservice)/register/action | Register the subscription for Microsoft.HybridContainerService |
238+
> | [Microsoft.HybridCompute](../permissions/hybrid-multicloud.md#microsofthybridcompute)/settings/write | Writes an Azure Arc settings |
239+
> | [Microsoft.HybridCompute](../permissions/hybrid-multicloud.md#microsofthybridcompute)/settings/read | Reads any Azure Arc settings |
240+
> | [Microsoft.HybridCompute](../permissions/hybrid-multicloud.md#microsofthybridcompute)/gateways/read | Reads any Azure Arc gateways |
241+
> | [Microsoft.HybridCompute](../permissions/hybrid-multicloud.md#microsofthybridcompute)/gateways/write | Writes an Azure Arc gateways |
242+
> | [Microsoft.HybridCompute](../permissions/hybrid-multicloud.md#microsofthybridcompute)/gateways/delete | Deletes an Azure Arc gateways |
238243
> | **NotActions** | |
239244
> | *none* | |
240245
> | **DataActions** | |
@@ -352,7 +357,12 @@ Grants full access to the cluster and its resources, including the ability to re
352357
"Microsoft.Resources/subscriptions/resourceGroups/read",
353358
"Microsoft.AzureStackHCI/StorageContainers/Write",
354359
"Microsoft.AzureStackHCI/StorageContainers/Read",
355-
"Microsoft.HybridContainerService/register/action"
360+
"Microsoft.HybridContainerService/register/action",
361+
"Microsoft.HybridCompute/settings/write",
362+
"Microsoft.HybridCompute/settings/read",
363+
"Microsoft.HybridCompute/gateways/read",
364+
"Microsoft.HybridCompute/gateways/write",
365+
"Microsoft.HybridCompute/gateways/delete"
356366
],
357367
"notActions": [],
358368
"dataActions": [],
@@ -567,7 +577,7 @@ Grants permissions to perform all VM actions
567577
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/write | Creates or updates an deployment. |
568578
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/delete | Deletes a deployment. |
569579
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/cancel/action | Cancels a deployment. |
570-
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/validate/action | Validates an deployment. |
580+
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/validate/action | Validates a deployment. |
571581
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/whatIf/action | Predicts template deployment changes. |
572582
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/exportTemplate/action | Export template for a deployment |
573583
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/operations/read | Gets or lists deployment operations. |

0 commit comments

Comments
 (0)