Skip to content

Commit d2a44dd

Browse files
Merge pull request #125455 from Iam-Manishkumar/Iam-Manishkumar/azure-docs
Add "Locks Contributor" Built-in Role to Security
2 parents af4b9a3 + 4806bd1 commit d2a44dd

File tree

2 files changed

+44
-1
lines changed

2 files changed

+44
-1
lines changed

articles/role-based-access-control/built-in-roles.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -446,6 +446,7 @@ The following table provides a brief description of each built-in role. Click th
446446
> | <a name='security-assessment-contributor'></a>[Security Assessment Contributor](./built-in-roles/security.md#security-assessment-contributor) | Lets you push assessments to Microsoft Defender for Cloud | 612c2aa1-cb24-443b-ac28-3ab7272de6f5 |
447447
> | <a name='security-manager-legacy'></a>[Security Manager (Legacy)](./built-in-roles/security.md#security-manager-legacy) | This is a legacy role. Please use Security Admin instead. | e3d13bf0-dd5a-482e-ba6b-9b8433878d10 |
448448
> | <a name='security-reader'></a>[Security Reader](./built-in-roles/security.md#security-reader) | View permissions for Microsoft Defender for Cloud. Can view recommendations, alerts, a security policy, and security states, but cannot make changes.<br><br>For Microsoft Defender for IoT, see [Azure user roles for OT and Enterprise IoT monitoring](/azure/defender-for-iot/organizations/roles-azure). | 39bc4728-0917-49c7-9d2c-d95423bc2eb4 |
449+
> | <a name='locks-contributor'></a>[Locks Contributor](./built-in-roles/security.md#locks-contributor) | Lets you manage locks operations | 28bf596f-4eb7-45ce-b5bc-6cf482fec137 |
449450
450451
## DevOps
451452

articles/role-based-access-control/built-in-roles/security.md

Lines changed: 43 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1559,7 +1559,49 @@ View permissions for Microsoft Defender for Cloud. Can view recommendations, ale
15591559
"type": "Microsoft.Authorization/roleDefinitions"
15601560
}
15611561
```
1562+
## Locks Contributor
1563+
1564+
Manage locks operations.
1565+
1566+
> [!div class="mx-tableFixed"]
1567+
> | Actions | Description |
1568+
> | --- | --- |
1569+
> | [Microsoft.Authorization](../permissions/management-and-governance.md#microsoftauthorization)/locks/read | Gets locks at the specified scope |
1570+
> | [Microsoft.Authorization](../permissions/management-and-governance.md#microsoftauthorization)/locks/write | Add locks at the specified scope |
1571+
> | [Microsoft.Authorization](../permissions/management-and-governance.md#microsoftauthorization)/locks/delete | Delete locks at the specified scope |
1572+
> | **NotActions** | |
1573+
> | *none* | |
1574+
> | **DataActions** | |
1575+
> | *none* | |
1576+
> | **NotDataActions** | |
1577+
> | *none* | |
1578+
1579+
```json
1580+
{
1581+
"assignableScopes": [
1582+
"/"
1583+
],
1584+
"description": "Can Manage Locks Operations.",
1585+
"id": "/providers/Microsoft.Authorization/roleDefinitions/28bf596f-4eb7-45ce-b5bc-6cf482fec137",
1586+
"name": "28bf596f-4eb7-45ce-b5bc-6cf482fec137",
1587+
"permissions": [
1588+
{
1589+
"actions": [
1590+
"Microsoft.Authorization/locks/read",
1591+
"Microsoft.Authorization/locks/write",
1592+
"Microsoft.Authorization/locks/delete"
1593+
],
1594+
"notActions": [],
1595+
"dataActions": [],
1596+
"notDataActions": []
1597+
}
1598+
],
1599+
"roleName": "Locks Contributor",
1600+
"roleType": "BuiltInRole",
1601+
"type": "Microsoft.Authorization/roleDefinitions"
1602+
}
1603+
```
15621604

15631605
## Next steps
15641606

1565-
- [Assign Azure roles using the Azure portal](/azure/role-based-access-control/role-assignments-portal)
1607+
- [Assign Azure roles using the Azure portal](/azure/role-based-access-control/role-assignments-portal)

0 commit comments

Comments
 (0)