You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/role-based-access-control/built-in-roles.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -136,9 +136,6 @@ The following table provides a brief description of each built-in role. Click th
136
136
> | <aname='media-services-media-operator'></a>[Media Services Media Operator](./built-in-roles/web-and-mobile.md#media-services-media-operator)| Create, read, modify, and delete Assets, Asset Filters, Streaming Locators, and Jobs; read-only access to other Media Services resources. | e4395492-1534-4db2-bedf-88c14621589c |
137
137
> | <aname='media-services-policy-administrator'></a>[Media Services Policy Administrator](./built-in-roles/web-and-mobile.md#media-services-policy-administrator)| Create, read, modify, and delete Account Filters, Streaming Policies, Content Key Policies, and Transforms; read-only access to other Media Services resources. Cannot create Jobs, Assets or Streaming resources. | c4bba371-dacd-4a26-b320-7250bca963ae |
138
138
> | <aname='media-services-streaming-endpoints-administrator'></a>[Media Services Streaming Endpoints Administrator](./built-in-roles/web-and-mobile.md#media-services-streaming-endpoints-administrator)| Create, read, modify, and delete Streaming Endpoints; read-only access to other Media Services resources. | 99dba123-b5fe-44d5-874c-ced7199a5804 |
139
-
> | <aname='search-index-data-contributor'></a>[Search Index Data Contributor](./built-in-roles/web-and-mobile.md#search-index-data-contributor)| Grants full access to Azure Cognitive Search index data. | 8ebe5a00-799e-43f5-93ac-243d3dce84a7 |
140
-
> | <aname='search-index-data-reader'></a>[Search Index Data Reader](./built-in-roles/web-and-mobile.md#search-index-data-reader)| Grants read access to Azure Cognitive Search index data. | 1407120a-92aa-4202-b7e9-c0e197c71c8f |
141
-
> | <aname='search-service-contributor'></a>[Search Service Contributor](./built-in-roles/web-and-mobile.md#search-service-contributor)| Lets you manage Search services, but not access to them. | 7ca78c08-252a-4471-8644-bb5ff32d4ba0 |
> | <aname='signalr-app-server'></a>[SignalR App Server](./built-in-roles/web-and-mobile.md#signalr-app-server)| Lets your app server access SignalR Service with AAD auth options. | 420fcaa2-552c-430f-98ca-3264be4806c7 |
144
141
> | <aname='signalr-rest-api-owner'></a>[SignalR REST API Owner](./built-in-roles/web-and-mobile.md#signalr-rest-api-owner)| Full access to Azure SignalR Service REST APIs | fd53cd77-2268-407a-8f46-7e7863d0f521 |
@@ -237,6 +234,9 @@ The following table provides a brief description of each built-in role. Click th
237
234
> | <aname='cognitive-services-qna-maker-reader'></a>[Cognitive Services QnA Maker Reader](./built-in-roles/ai-machine-learning.md#cognitive-services-qna-maker-reader)| Let's you read and test a KB only. | 466ccd10-b268-4a11-b098-b4849f024126 |
> | <aname='cognitive-services-user'></a>[Cognitive Services User](./built-in-roles/ai-machine-learning.md#cognitive-services-user)| Lets you read and list keys of Cognitive Services. | a97b65f3-24c7-4388-baec-2e87135dc908 |
237
+
> | <aname='search-index-data-contributor'></a>[Search Index Data Contributor](./built-in-roles/ai-machine-learning.md#search-index-data-contributor)| Grants full access to Azure Cognitive Search index data. | 8ebe5a00-799e-43f5-93ac-243d3dce84a7 |
238
+
> | <aname='search-index-data-reader'></a>[Search Index Data Reader](./built-in-roles/ai-machine-learning.md#search-index-data-reader)| Grants read access to Azure Cognitive Search index data. | 1407120a-92aa-4202-b7e9-c0e197c71c8f |
239
+
> | <aname='search-service-contributor'></a>[Search Service Contributor](./built-in-roles/ai-machine-learning.md#search-service-contributor)| Lets you manage Search services, but not access to them. | 7ca78c08-252a-4471-8644-bb5ff32d4ba0 |
> |[Microsoft.ResourceHealth](../permissions/general.md#microsoftresourcehealth)/availabilityStatuses/read | Gets the availability statuses for all resources in the specified scope |
148
+
> |[Microsoft.ResourceHealth](../permissions/management-and-governance.md#microsoftresourcehealth)/availabilityStatuses/read | Gets the availability statuses for all resources in the specified scope |
149
149
> |[Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/*| Create and manage a deployment |
150
150
> |[Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/operations/read | Gets or lists deployment operations. |
151
151
> |[Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/subscriptions/operationresults/read | Get the subscription operation results. |
@@ -986,7 +986,7 @@ Lets you read and list keys of Cognitive Services.
> |[Microsoft.ResourceHealth](../permissions/general.md#microsoftresourcehealth)/availabilityStatuses/read | Gets the availability statuses for all resources in the specified scope |
989
+
> |[Microsoft.ResourceHealth](../permissions/management-and-governance.md#microsoftresourcehealth)/availabilityStatuses/read | Gets the availability statuses for all resources in the specified scope |
990
990
> |[Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/operations/read | Gets or lists deployment operations. |
991
991
> |[Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/subscriptions/operationresults/read | Get the subscription operation results. |
992
992
> |[Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/subscriptions/read | Gets the list of subscriptions. |
@@ -1037,6 +1037,137 @@ Lets you read and list keys of Cognitive Services.
1037
1037
}
1038
1038
```
1039
1039
1040
+
## Search Index Data Contributor
1041
+
1042
+
Grants full access to Azure Cognitive Search index data.
Grants read access to Azure Cognitive Search index data.
1082
+
1083
+
> [!div class="mx-tableFixed"]
1084
+
> | Actions | Description |
1085
+
> | --- | --- |
1086
+
> |*none*||
1087
+
> |**NotActions**||
1088
+
> |*none*||
1089
+
> |**DataActions**||
1090
+
> |[Microsoft.Search](../permissions/ai-machine-learning.md#microsoftsearch)/searchServices/indexes/documents/read | Read documents or suggested query terms from an index. |
1091
+
> |**NotDataActions**||
1092
+
> |*none*||
1093
+
1094
+
```json
1095
+
{
1096
+
"assignableScopes": [
1097
+
"/"
1098
+
],
1099
+
"description": "Grants read access to Azure Cognitive Search index data.",
Lets you manage Search services, but not access to them.
1121
+
1122
+
[Learn more](/azure/search/search-security-rbac)
1123
+
1124
+
> [!div class="mx-tableFixed"]
1125
+
> | Actions | Description |
1126
+
> | --- | --- |
1127
+
> |[Microsoft.Authorization](../permissions/management-and-governance.md#microsoftauthorization)/*/read | Read roles and role assignments |
1128
+
> |[Microsoft.Insights](../permissions/monitor.md#microsoftinsights)/alertRules/*| Create and manage a classic metric alert |
1129
+
> |[Microsoft.ResourceHealth](../permissions/management-and-governance.md#microsoftresourcehealth)/availabilityStatuses/read | Gets the availability statuses for all resources in the specified scope |
1130
+
> |[Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/*| Create and manage a deployment |
1131
+
> |[Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/subscriptions/resourceGroups/read | Gets or lists resource groups. |
1132
+
> |[Microsoft.Search](../permissions/ai-machine-learning.md#microsoftsearch)/searchServices/*| Create and manage search services |
1133
+
> |[Microsoft.Support](../permissions/general.md#microsoftsupport)/*| Create and update a support ticket |
1134
+
> |**NotActions**||
1135
+
> |*none*||
1136
+
> |**DataActions**||
1137
+
> |*none*||
1138
+
> |**NotDataActions**||
1139
+
> |*none*||
1140
+
1141
+
```json
1142
+
{
1143
+
"assignableScopes": [
1144
+
"/"
1145
+
],
1146
+
"description": "Lets you manage Search services, but not access to them.",
@@ -155,10 +155,10 @@ Create and manage data factories, as well as child resources within them.
155
155
> | Actions | Description |
156
156
> | --- | --- |
157
157
> |[Microsoft.Authorization](../permissions/management-and-governance.md#microsoftauthorization)/*/read | Read roles and role assignments |
158
-
> |[Microsoft.DataFactory](../permissions/databases.md#microsoftdatafactory)/dataFactories/*| Create and manage data factories, and child resources within them. |
159
-
> |[Microsoft.DataFactory](../permissions/databases.md#microsoftdatafactory)/factories/*| Create and manage data factories, and child resources within them. |
158
+
> |[Microsoft.DataFactory](../permissions/analytics.md#microsoftdatafactory)/dataFactories/*| Create and manage data factories, and child resources within them. |
159
+
> |[Microsoft.DataFactory](../permissions/analytics.md#microsoftdatafactory)/factories/*| Create and manage data factories, and child resources within them. |
160
160
> |[Microsoft.Insights](../permissions/monitor.md#microsoftinsights)/alertRules/*| Create and manage a classic metric alert |
161
-
> |[Microsoft.ResourceHealth](../permissions/general.md#microsoftresourcehealth)/availabilityStatuses/read | Gets the availability statuses for all resources in the specified scope |
161
+
> |[Microsoft.ResourceHealth](../permissions/management-and-governance.md#microsoftresourcehealth)/availabilityStatuses/read | Gets the availability statuses for all resources in the specified scope |
162
162
> |[Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/*| Create and manage a deployment |
163
163
> |[Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/subscriptions/resourceGroups/read | Gets or lists resource groups. |
164
164
> |[Microsoft.Support](../permissions/general.md#microsoftsupport)/*| Create and update a support ticket |
@@ -472,11 +472,11 @@ Read, write, and delete Schema Registry groups and schemas.
@@ -513,11 +513,11 @@ Read and list Schema Registry groups and schemas.
513
513
> [!div class="mx-tableFixed"]
514
514
> | Actions | Description |
515
515
> | --- | --- |
516
-
> |[Microsoft.EventHub](../permissions/analytics.md#microsofteventhub)/namespaces/schemagroups/read | Get list of SchemaGroup Resource Descriptions |
516
+
> |[Microsoft.EventHub](../permissions/integration.md#microsofteventhub)/namespaces/schemagroups/read | Get list of SchemaGroup Resource Descriptions |
0 commit comments