You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/role-based-access-control/built-in-roles.md
+16-10Lines changed: 16 additions & 10 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,7 +12,7 @@ ms.devlang:
12
12
ms.topic: reference
13
13
ms.tgt_pltfrm:
14
14
ms.workload: identity
15
-
ms.date: 04/15/2020
15
+
ms.date: 05/04/2020
16
16
ms.author: rolyon
17
17
ms.reviewer: bagovind
18
18
@@ -77,7 +77,7 @@ The following table provides a brief description and the unique ID of each built
77
77
> |[Storage Queue Data Message Sender](#storage-queue-data-message-sender)| Add messages to an Azure Storage queue. To learn which actions are required for a given data operation, see [Permissions for calling blob and queue data operations](https://docs.microsoft.com/rest/api/storageservices/authenticate-with-azure-active-directory#permissions-for-calling-blob-and-queue-data-operations). | c6a89b2d-59bc-44d0-9896-0f6e12d7b80a |
78
78
> |[Storage Queue Data Reader](#storage-queue-data-reader)| Read and list Azure Storage queues and queue messages. To learn which actions are required for a given data operation, see [Permissions for calling blob and queue data operations](https://docs.microsoft.com/rest/api/storageservices/authenticate-with-azure-active-directory#permissions-for-calling-blob-and-queue-data-operations). | 19e7f393-937e-4f77-808e-94535e297925 |
79
79
> |**Web**|||
80
-
> |[Azure Maps Data Reader (Preview)](#azure-maps-data-reader-preview)| Grants access to read map related data from an Azure maps account. | 423170ca-a8f6-4b0f-8487-9e4eb8f49bfa |
80
+
> |[Azure Maps Data Reader](#azure-maps-data-reader)| Grants access to read map related data from an Azure maps account. | 423170ca-a8f6-4b0f-8487-9e4eb8f49bfa |
81
81
> |[Search Service Contributor](#search-service-contributor)| Lets you manage Search services, but not access to them. | 7ca78c08-252a-4471-8644-bb5ff32d4ba0 |
82
82
> |[Web Plan Contributor](#web-plan-contributor)| Lets you manage the web plans for websites, but not access to them. | 2cc479cb-7b4d-49a8-b449-8c00fd0f0a4b |
83
83
> |[Website Contributor](#website-contributor)| Lets you manage websites (not web plans), but not access to them. | de139f84-1756-47ae-9be6-808fbbe84772 |
@@ -143,10 +143,10 @@ The following table provides a brief description and the unique ID of each built
> |[Security Admin](#security-admin)|View and update permissions for Security Center. Same permissions as the Security Reader role and can also update the security policy and dismiss alerts and recommendations. | fb1c8493-542b-48eb-b624-b4c8fea62acd |
147
147
> |[Security Assessment Contributor](#security-assessment-contributor)| Lets you push assessments to Security Center | 612c2aa1-cb24-443b-ac28-3ab7272de6f5 |
148
148
> |[Security Manager (Legacy)](#security-manager-legacy)| This is a legacy role. Please use Security Admin instead. | e3d13bf0-dd5a-482e-ba6b-9b8433878d10 |
149
-
> |[Security Reader](#security-reader)| Can view recommendations and alerts, view security policies, view security states, but cannot make changes. | 39bc4728-0917-49c7-9d2c-d95423bc2eb4 |
149
+
> |[Security Reader](#security-reader)|View permissions for Security Center. Can view recommendations, alerts, a security policy, and security states, but cannot make changes. | 39bc4728-0917-49c7-9d2c-d95423bc2eb4 |
150
150
> |**DevOps**|||
151
151
> |[DevTest Labs User](#devtest-labs-user)| Lets you connect, start, restart, and shutdown your virtual machines in your Azure DevTest Labs. | 76283e04-6283-4c54-8f91-bcf1374a3c64 |
152
152
> |[Lab Creator](#lab-creator)| Lets you create, manage, delete your managed labs under your Azure Lab Accounts. | b97fb8bc-a8b2-4522-a38b-dd33c7e65ead |
@@ -2539,7 +2539,7 @@ Read and list Azure Storage queues and queue messages. To learn which actions ar
2539
2539
## Web
2540
2540
2541
2541
2542
-
### Azure Maps Data Reader (Preview)
2542
+
### Azure Maps Data Reader
2543
2543
2544
2544
Grants access to read map related data from an Azure maps account.
2545
2545
@@ -2551,7 +2551,7 @@ Grants access to read map related data from an Azure maps account.
2551
2551
> |**NotActions**||
2552
2552
> |*none*||
2553
2553
> |**DataActions**||
2554
-
> | Microsoft.Maps/accounts/data/read |Grants data read access to a maps account.|
2554
+
> | Microsoft.Maps/accounts/*/read ||
2555
2555
> |**NotDataActions**||
2556
2556
> |*none*||
2557
2557
@@ -2568,12 +2568,12 @@ Grants access to read map related data from an Azure maps account.
2568
2568
"actions": [],
2569
2569
"notActions": [],
2570
2570
"dataActions": [
2571
-
"Microsoft.Maps/accounts/data/read"
2571
+
"Microsoft.Maps/accounts/*/read"
2572
2572
],
2573
2573
"notDataActions": []
2574
2574
}
2575
2575
],
2576
-
"roleName": "Azure Maps Data Reader (Preview)",
2576
+
"roleName": "Azure Maps Data Reader",
2577
2577
"roleType": "BuiltInRole",
2578
2578
"type": "Microsoft.Authorization/roleDefinitions"
2579
2579
}
@@ -5706,7 +5706,7 @@ Lets you manage key vaults, but not access to them.
5706
5706
5707
5707
### Security Admin
5708
5708
5709
-
Can view security policies, view security states, edit security policies, view alerts and recommendations, dismiss alerts and recommendations.
5709
+
View and update permissions for Security Center. Same permissions as the Security Reader role and can also update the security policy and dismiss alerts and recommendations.
5710
5710
5711
5711
> [!div class="mx-tableFixed"]
5712
5712
> |||
@@ -5864,7 +5864,7 @@ This is a legacy role. Please use Security Admin instead.
5864
5864
5865
5865
### Security Reader
5866
5866
5867
-
Can view recommendations and alerts, view security policies, view security states, but cannot make changes.
5867
+
View permissions for Security Center. Can view recommendations, alerts, a security policy, and security states, but cannot make changes.
5868
5868
5869
5869
> [!div class="mx-tableFixed"]
5870
5870
> |||
@@ -6213,6 +6213,9 @@ Can read all monitoring data and edit monitoring settings. See also [Get started
6213
6213
> | Microsoft.Insights/scheduledqueryrules/*||
6214
6214
> | Microsoft.Insights/webtests/*| Create and manage Insights web tests |
> | Microsoft.OperationalInsights/workspaces/write | Creates a new workspace or links to an existing workspace by providing the customer id from the existing workspace. |
0 commit comments