Skip to content

Commit 882e691

Browse files
authored
Update built-in-roles.md
1 parent 4f4ffdf commit 882e691

File tree

1 file changed

+41
-40
lines changed

1 file changed

+41
-40
lines changed

articles/key-vault/managed-hsm/built-in-roles.md

Lines changed: 41 additions & 40 deletions
Original file line numberDiff line numberDiff line change
@@ -29,8 +29,9 @@ To manage control plane permissions for the Managed HSM resource, you must use [
2929
|Managed HSM Policy Administrator| Grants permissions to create and delete role assignments.|4bd23610-cdcf-4971-bdee-bdc562cc28e4|
3030
|Managed HSM Crypto Auditor|Grants read permissions to read (but not use) key attributes.|2c18b078-7c48-4d3a-af88-5a3a1b3f82b3|
3131
|Managed HSM Crypto Service Encryption User| Grants permissions to use a key for service encryption. |33413926-3206-4cdd-b39a-83574fe37a17|
32-
|Managed HSM Backup| Grants permissions to perform single-key or whole-HSM backup.|7b127d3c-77bd-4e3e-bbe0-dbb8971fa7f8|
3332
|Managed HSM Crypto Service Release User| Grants permissions to release a key to a trusted execution environment. |21dbd100-6940-42c2-9190-5d6cb909625c|
33+
|Managed HSM Backup| Grants permissions to perform single-key or whole-HSM backup.|7b127d3c-77bd-4e3e-bbe0-dbb8971fa7f8|
34+
|Managed HSM Restore| Grants permissions to perform single-key or whole-HSM restore. |6efe6056-5259-49d2-8b3d-d3d73544b20b|
3435

3536
## Permitted operations
3637

@@ -39,45 +40,45 @@ To manage control plane permissions for the Managed HSM resource, you must use [
3940
> - All the data action names have the prefix **Microsoft.KeyVault/managedHsm**, which is omitted in the table for brevity.
4041
> - All role names have the prefix **Managed HSM**, which is omitted in the following table for brevity.
4142
42-
|Data action | Administrator | Crypto Officer | Crypto User | Policy Administrator | Crypto Service Encryption User | Backup | Crypto Auditor| Crypto Service Released User|
43-
|---|:---:|:---:|:---:|:---:|:---:|:---:|:---:|:---:|
44-
|**Security domain management**|||||||||
45-
|/securitydomain/download/action|X||||||||
46-
|/securitydomain/upload/action|X||||||||
47-
|/securitydomain/upload/read|X||||||||
48-
|/securitydomain/transferkey/read|X||||||||
49-
|**Key management**|||||||||
50-
|/keys/read/action|||X||X||X||
51-
|/keys/write/action|||X||||||
52-
|/keys/rotate/action|||X||||||
53-
|/keys/create|||X||||||
54-
|/keys/delete|||X||||||
55-
|/keys/deletedKeys/read/action||X|||||||
56-
|/keys/deletedKeys/recover/action||X|||||||
57-
|/keys/deletedKeys/delete||X|||||X||
58-
|/keys/backup/action|||X|||X|||
59-
|/keys/restore/action|||X||||||
60-
|/keys/release/action|||X|||||X |
61-
|/keys/import/action|||X||||||
62-
|**Key cryptographic operations**|||||||||
63-
|/keys/encrypt/action|||X||||||
64-
|/keys/decrypt/action|||X||||||
65-
|/keys/wrap/action|||X||X||||
66-
|/keys/unwrap/action|||X||X||||
67-
|/keys/sign/action|||X||||||
68-
|/keys/verify/action|||X||||||
69-
|**Role management**|||||||||
70-
|/roleAssignments/read/action|X|X|X|X|||X||
71-
|/roleAssignments/write/action|X|X||X|||||
72-
|/roleAssignments/delete/action|X|X||X|||||
73-
|/roleDefinitions/read/action|X|X|X|X|||X||
74-
|/roleDefinitions/write/action|X|X||X|||||
75-
|/roleDefinitions/delete/action|X|X||X|||||
76-
|**Backup and restore management**|||||||||
77-
|/backup/start/action|X|||||X|||
78-
|/backup/status/action|X|||||X|||
79-
|/restore/start/action|X||||||||
80-
|/restore/status/action|X||||||||
43+
|Data action | Administrator | Crypto Officer | Crypto User | Policy Administrator | Crypto Service Encryption User | Backup | Crypto Auditor | Crypto Service Release User | Restore|
44+
|---|:---:|:---:|:---:|:---:|:---:|:---:|:---:|:---:|:---:|
45+
|**Security domain management**||||||||||
46+
|/securitydomain/download/action|X|||||||||
47+
|/securitydomain/upload/action|X|||||||||
48+
|/securitydomain/upload/read|X|||||||||
49+
|/securitydomain/transferkey/read|X|||||||||
50+
|**Key management**||||||||||
51+
|/keys/read/action|||X||X||X|||
52+
|/keys/write/action|||X|||||||
53+
|/keys/rotate/action|||X|||||||
54+
|/keys/create|||X|||||||
55+
|/keys/delete|||X|||||||
56+
|/keys/deletedKeys/read/action||X||||||||
57+
|/keys/deletedKeys/recover/action||X||||||||
58+
|/keys/deletedKeys/delete||X|||||X|||
59+
|/keys/backup/action|||X|||X||||
60+
|/keys/restore/action|||X||||||X|
61+
|/keys/release/action|||X|||||X||
62+
|/keys/import/action|||X|||||||
63+
|**Key cryptographic operations**||||||||||
64+
|/keys/encrypt/action|||X|||||||
65+
|/keys/decrypt/action|||X|||||||
66+
|/keys/wrap/action|||X||X|||||
67+
|/keys/unwrap/action|||X||X|||||
68+
|/keys/sign/action|||X|||||||
69+
|/keys/verify/action|||X|||||||
70+
|**Role management**||||||||||
71+
|/roleAssignments/read/action|X|X|X|X|||X|||
72+
|/roleAssignments/write/action|X|X||X||||||
73+
|/roleAssignments/delete/action|X|X||X||||||
74+
|/roleDefinitions/read/action|X|X|X|X|||X|||
75+
|/roleDefinitions/write/action|X|X||X||||||
76+
|/roleDefinitions/delete/action|X|X||X||||||
77+
|**Backup and restore management**||||||||||
78+
|/backup/start/action|X|||||X||||
79+
|/backup/status/action|X|||||X||||
80+
|/restore/start/action|X||||||||X|
81+
|/restore/status/action|X||||||||X|
8182

8283
## Next steps
8384

0 commit comments

Comments
 (0)