Skip to content

Commit f5b6d18

Browse files
committed
Update provider categories
1 parent ad08134 commit f5b6d18

31 files changed

+2038
-2093
lines changed

articles/role-based-access-control/built-in-roles.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -136,9 +136,6 @@ The following table provides a brief description of each built-in role. Click th
136136
> | <a name='media-services-media-operator'></a>[Media Services Media Operator](./built-in-roles/web-and-mobile.md#media-services-media-operator) | Create, read, modify, and delete Assets, Asset Filters, Streaming Locators, and Jobs; read-only access to other Media Services resources. | e4395492-1534-4db2-bedf-88c14621589c |
137137
> | <a name='media-services-policy-administrator'></a>[Media Services Policy Administrator](./built-in-roles/web-and-mobile.md#media-services-policy-administrator) | Create, read, modify, and delete Account Filters, Streaming Policies, Content Key Policies, and Transforms; read-only access to other Media Services resources. Cannot create Jobs, Assets or Streaming resources. | c4bba371-dacd-4a26-b320-7250bca963ae |
138138
> | <a name='media-services-streaming-endpoints-administrator'></a>[Media Services Streaming Endpoints Administrator](./built-in-roles/web-and-mobile.md#media-services-streaming-endpoints-administrator) | Create, read, modify, and delete Streaming Endpoints; read-only access to other Media Services resources. | 99dba123-b5fe-44d5-874c-ced7199a5804 |
139-
> | <a name='search-index-data-contributor'></a>[Search Index Data Contributor](./built-in-roles/web-and-mobile.md#search-index-data-contributor) | Grants full access to Azure Cognitive Search index data. | 8ebe5a00-799e-43f5-93ac-243d3dce84a7 |
140-
> | <a name='search-index-data-reader'></a>[Search Index Data Reader](./built-in-roles/web-and-mobile.md#search-index-data-reader) | Grants read access to Azure Cognitive Search index data. | 1407120a-92aa-4202-b7e9-c0e197c71c8f |
141-
> | <a name='search-service-contributor'></a>[Search Service Contributor](./built-in-roles/web-and-mobile.md#search-service-contributor) | Lets you manage Search services, but not access to them. | 7ca78c08-252a-4471-8644-bb5ff32d4ba0 |
142139
> | <a name='signalr-accesskey-reader'></a>[SignalR AccessKey Reader](./built-in-roles/web-and-mobile.md#signalr-accesskey-reader) | Read SignalR Service Access Keys | 04165923-9d83-45d5-8227-78b77b0a687e |
143140
> | <a name='signalr-app-server'></a>[SignalR App Server](./built-in-roles/web-and-mobile.md#signalr-app-server) | Lets your app server access SignalR Service with AAD auth options. | 420fcaa2-552c-430f-98ca-3264be4806c7 |
144141
> | <a name='signalr-rest-api-owner'></a>[SignalR REST API Owner](./built-in-roles/web-and-mobile.md#signalr-rest-api-owner) | Full access to Azure SignalR Service REST APIs | fd53cd77-2268-407a-8f46-7e7863d0f521 |
@@ -237,6 +234,9 @@ The following table provides a brief description of each built-in role. Click th
237234
> | <a name='cognitive-services-qna-maker-reader'></a>[Cognitive Services QnA Maker Reader](./built-in-roles/ai-machine-learning.md#cognitive-services-qna-maker-reader) | Let's you read and test a KB only. | 466ccd10-b268-4a11-b098-b4849f024126 |
238235
> | <a name='cognitive-services-usages-reader'></a>[Cognitive Services Usages Reader](./built-in-roles/ai-machine-learning.md#cognitive-services-usages-reader) | Minimal permission to view Cognitive Services usages. | bba48692-92b0-4667-a9ad-c31c7b334ac2 |
239236
> | <a name='cognitive-services-user'></a>[Cognitive Services User](./built-in-roles/ai-machine-learning.md#cognitive-services-user) | Lets you read and list keys of Cognitive Services. | a97b65f3-24c7-4388-baec-2e87135dc908 |
237+
> | <a name='search-index-data-contributor'></a>[Search Index Data Contributor](./built-in-roles/ai-machine-learning.md#search-index-data-contributor) | Grants full access to Azure Cognitive Search index data. | 8ebe5a00-799e-43f5-93ac-243d3dce84a7 |
238+
> | <a name='search-index-data-reader'></a>[Search Index Data Reader](./built-in-roles/ai-machine-learning.md#search-index-data-reader) | Grants read access to Azure Cognitive Search index data. | 1407120a-92aa-4202-b7e9-c0e197c71c8f |
239+
> | <a name='search-service-contributor'></a>[Search Service Contributor](./built-in-roles/ai-machine-learning.md#search-service-contributor) | Lets you manage Search services, but not access to them. | 7ca78c08-252a-4471-8644-bb5ff32d4ba0 |
240240
241241
## Internet of Things
242242

articles/role-based-access-control/built-in-roles/ai-machine-learning.md

Lines changed: 133 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -145,7 +145,7 @@ Lets you create, read, update, delete and manage keys of Cognitive Services.
145145
> | [Microsoft.Insights](../permissions/monitor.md#microsoftinsights)/logDefinitions/read | Read log definitions |
146146
> | [Microsoft.Insights](../permissions/monitor.md#microsoftinsights)/metricdefinitions/read | Read metric definitions |
147147
> | [Microsoft.Insights](../permissions/monitor.md#microsoftinsights)/metrics/read | Read metrics |
148-
> | [Microsoft.ResourceHealth](../permissions/general.md#microsoftresourcehealth)/availabilityStatuses/read | Gets the availability statuses for all resources in the specified scope |
148+
> | [Microsoft.ResourceHealth](../permissions/management-and-governance.md#microsoftresourcehealth)/availabilityStatuses/read | Gets the availability statuses for all resources in the specified scope |
149149
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/* | Create and manage a deployment |
150150
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/operations/read | Gets or lists deployment operations. |
151151
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/subscriptions/operationresults/read | Get the subscription operation results. |
@@ -986,7 +986,7 @@ Lets you read and list keys of Cognitive Services.
986986
> | [Microsoft.Insights](../permissions/monitor.md#microsoftinsights)/logDefinitions/read | Read log definitions |
987987
> | [Microsoft.Insights](../permissions/monitor.md#microsoftinsights)/metricdefinitions/read | Read metric definitions |
988988
> | [Microsoft.Insights](../permissions/monitor.md#microsoftinsights)/metrics/read | Read metrics |
989-
> | [Microsoft.ResourceHealth](../permissions/general.md#microsoftresourcehealth)/availabilityStatuses/read | Gets the availability statuses for all resources in the specified scope |
989+
> | [Microsoft.ResourceHealth](../permissions/management-and-governance.md#microsoftresourcehealth)/availabilityStatuses/read | Gets the availability statuses for all resources in the specified scope |
990990
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/operations/read | Gets or lists deployment operations. |
991991
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/subscriptions/operationresults/read | Get the subscription operation results. |
992992
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/subscriptions/read | Gets the list of subscriptions. |
@@ -1037,6 +1037,137 @@ Lets you read and list keys of Cognitive Services.
10371037
}
10381038
```
10391039

1040+
## Search Index Data Contributor
1041+
1042+
Grants full access to Azure Cognitive Search index data.
1043+
1044+
> [!div class="mx-tableFixed"]
1045+
> | Actions | Description |
1046+
> | --- | --- |
1047+
> | *none* | |
1048+
> | **NotActions** | |
1049+
> | *none* | |
1050+
> | **DataActions** | |
1051+
> | [Microsoft.Search](../permissions/ai-machine-learning.md#microsoftsearch)/searchServices/indexes/documents/* | |
1052+
> | **NotDataActions** | |
1053+
> | *none* | |
1054+
1055+
```json
1056+
{
1057+
"assignableScopes": [
1058+
"/"
1059+
],
1060+
"description": "Grants full access to Azure Cognitive Search index data.",
1061+
"id": "/providers/Microsoft.Authorization/roleDefinitions/8ebe5a00-799e-43f5-93ac-243d3dce84a7",
1062+
"name": "8ebe5a00-799e-43f5-93ac-243d3dce84a7",
1063+
"permissions": [
1064+
{
1065+
"actions": [],
1066+
"notActions": [],
1067+
"dataActions": [
1068+
"Microsoft.Search/searchServices/indexes/documents/*"
1069+
],
1070+
"notDataActions": []
1071+
}
1072+
],
1073+
"roleName": "Search Index Data Contributor",
1074+
"roleType": "BuiltInRole",
1075+
"type": "Microsoft.Authorization/roleDefinitions"
1076+
}
1077+
```
1078+
1079+
## Search Index Data Reader
1080+
1081+
Grants read access to Azure Cognitive Search index data.
1082+
1083+
> [!div class="mx-tableFixed"]
1084+
> | Actions | Description |
1085+
> | --- | --- |
1086+
> | *none* | |
1087+
> | **NotActions** | |
1088+
> | *none* | |
1089+
> | **DataActions** | |
1090+
> | [Microsoft.Search](../permissions/ai-machine-learning.md#microsoftsearch)/searchServices/indexes/documents/read | Read documents or suggested query terms from an index. |
1091+
> | **NotDataActions** | |
1092+
> | *none* | |
1093+
1094+
```json
1095+
{
1096+
"assignableScopes": [
1097+
"/"
1098+
],
1099+
"description": "Grants read access to Azure Cognitive Search index data.",
1100+
"id": "/providers/Microsoft.Authorization/roleDefinitions/1407120a-92aa-4202-b7e9-c0e197c71c8f",
1101+
"name": "1407120a-92aa-4202-b7e9-c0e197c71c8f",
1102+
"permissions": [
1103+
{
1104+
"actions": [],
1105+
"notActions": [],
1106+
"dataActions": [
1107+
"Microsoft.Search/searchServices/indexes/documents/read"
1108+
],
1109+
"notDataActions": []
1110+
}
1111+
],
1112+
"roleName": "Search Index Data Reader",
1113+
"roleType": "BuiltInRole",
1114+
"type": "Microsoft.Authorization/roleDefinitions"
1115+
}
1116+
```
1117+
1118+
## Search Service Contributor
1119+
1120+
Lets you manage Search services, but not access to them.
1121+
1122+
[Learn more](/azure/search/search-security-rbac)
1123+
1124+
> [!div class="mx-tableFixed"]
1125+
> | Actions | Description |
1126+
> | --- | --- |
1127+
> | [Microsoft.Authorization](../permissions/management-and-governance.md#microsoftauthorization)/*/read | Read roles and role assignments |
1128+
> | [Microsoft.Insights](../permissions/monitor.md#microsoftinsights)/alertRules/* | Create and manage a classic metric alert |
1129+
> | [Microsoft.ResourceHealth](../permissions/management-and-governance.md#microsoftresourcehealth)/availabilityStatuses/read | Gets the availability statuses for all resources in the specified scope |
1130+
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/* | Create and manage a deployment |
1131+
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/subscriptions/resourceGroups/read | Gets or lists resource groups. |
1132+
> | [Microsoft.Search](../permissions/ai-machine-learning.md#microsoftsearch)/searchServices/* | Create and manage search services |
1133+
> | [Microsoft.Support](../permissions/general.md#microsoftsupport)/* | Create and update a support ticket |
1134+
> | **NotActions** | |
1135+
> | *none* | |
1136+
> | **DataActions** | |
1137+
> | *none* | |
1138+
> | **NotDataActions** | |
1139+
> | *none* | |
1140+
1141+
```json
1142+
{
1143+
"assignableScopes": [
1144+
"/"
1145+
],
1146+
"description": "Lets you manage Search services, but not access to them.",
1147+
"id": "/providers/Microsoft.Authorization/roleDefinitions/7ca78c08-252a-4471-8644-bb5ff32d4ba0",
1148+
"name": "7ca78c08-252a-4471-8644-bb5ff32d4ba0",
1149+
"permissions": [
1150+
{
1151+
"actions": [
1152+
"Microsoft.Authorization/*/read",
1153+
"Microsoft.Insights/alertRules/*",
1154+
"Microsoft.ResourceHealth/availabilityStatuses/read",
1155+
"Microsoft.Resources/deployments/*",
1156+
"Microsoft.Resources/subscriptions/resourceGroups/read",
1157+
"Microsoft.Search/searchServices/*",
1158+
"Microsoft.Support/*"
1159+
],
1160+
"notActions": [],
1161+
"dataActions": [],
1162+
"notDataActions": []
1163+
}
1164+
],
1165+
"roleName": "Search Service Contributor",
1166+
"roleType": "BuiltInRole",
1167+
"type": "Microsoft.Authorization/roleDefinitions"
1168+
}
1169+
```
1170+
10401171
## Next steps
10411172

10421173
- [Assign Azure roles using the Azure portal](/azure/role-based-access-control/role-assignments-portal)

articles/role-based-access-control/built-in-roles/analytics.md

Lines changed: 17 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -25,11 +25,11 @@ Allows for full access to Azure Event Hubs resources.
2525
> [!div class="mx-tableFixed"]
2626
> | Actions | Description |
2727
> | --- | --- |
28-
> | [Microsoft.EventHub](../permissions/analytics.md#microsofteventhub)/* | |
28+
> | [Microsoft.EventHub](../permissions/integration.md#microsofteventhub)/* | |
2929
> | **NotActions** | |
3030
> | *none* | |
3131
> | **DataActions** | |
32-
> | [Microsoft.EventHub](../permissions/analytics.md#microsofteventhub)/* | |
32+
> | [Microsoft.EventHub](../permissions/integration.md#microsofteventhub)/* | |
3333
> | **NotDataActions** | |
3434
> | *none* | |
3535
@@ -68,11 +68,11 @@ Allows receive access to Azure Event Hubs resources.
6868
> [!div class="mx-tableFixed"]
6969
> | Actions | Description |
7070
> | --- | --- |
71-
> | [Microsoft.EventHub](../permissions/analytics.md#microsofteventhub)/*/eventhubs/consumergroups/read | |
71+
> | [Microsoft.EventHub](../permissions/integration.md#microsofteventhub)/*/eventhubs/consumergroups/read | |
7272
> | **NotActions** | |
7373
> | *none* | |
7474
> | **DataActions** | |
75-
> | [Microsoft.EventHub](../permissions/analytics.md#microsofteventhub)/*/receive/action | |
75+
> | [Microsoft.EventHub](../permissions/integration.md#microsofteventhub)/*/receive/action | |
7676
> | **NotDataActions** | |
7777
> | *none* | |
7878
@@ -111,11 +111,11 @@ Allows send access to Azure Event Hubs resources.
111111
> [!div class="mx-tableFixed"]
112112
> | Actions | Description |
113113
> | --- | --- |
114-
> | [Microsoft.EventHub](../permissions/analytics.md#microsofteventhub)/*/eventhubs/read | |
114+
> | [Microsoft.EventHub](../permissions/integration.md#microsofteventhub)/*/eventhubs/read | |
115115
> | **NotActions** | |
116116
> | *none* | |
117117
> | **DataActions** | |
118-
> | [Microsoft.EventHub](../permissions/analytics.md#microsofteventhub)/*/send/action | |
118+
> | [Microsoft.EventHub](../permissions/integration.md#microsofteventhub)/*/send/action | |
119119
> | **NotDataActions** | |
120120
> | *none* | |
121121
@@ -155,10 +155,10 @@ Create and manage data factories, as well as child resources within them.
155155
> | Actions | Description |
156156
> | --- | --- |
157157
> | [Microsoft.Authorization](../permissions/management-and-governance.md#microsoftauthorization)/*/read | Read roles and role assignments |
158-
> | [Microsoft.DataFactory](../permissions/databases.md#microsoftdatafactory)/dataFactories/* | Create and manage data factories, and child resources within them. |
159-
> | [Microsoft.DataFactory](../permissions/databases.md#microsoftdatafactory)/factories/* | Create and manage data factories, and child resources within them. |
158+
> | [Microsoft.DataFactory](../permissions/analytics.md#microsoftdatafactory)/dataFactories/* | Create and manage data factories, and child resources within them. |
159+
> | [Microsoft.DataFactory](../permissions/analytics.md#microsoftdatafactory)/factories/* | Create and manage data factories, and child resources within them. |
160160
> | [Microsoft.Insights](../permissions/monitor.md#microsoftinsights)/alertRules/* | Create and manage a classic metric alert |
161-
> | [Microsoft.ResourceHealth](../permissions/general.md#microsoftresourcehealth)/availabilityStatuses/read | Gets the availability statuses for all resources in the specified scope |
161+
> | [Microsoft.ResourceHealth](../permissions/management-and-governance.md#microsoftresourcehealth)/availabilityStatuses/read | Gets the availability statuses for all resources in the specified scope |
162162
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/* | Create and manage a deployment |
163163
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/subscriptions/resourceGroups/read | Gets or lists resource groups. |
164164
> | [Microsoft.Support](../permissions/general.md#microsoftsupport)/* | Create and update a support ticket |
@@ -472,11 +472,11 @@ Read, write, and delete Schema Registry groups and schemas.
472472
> [!div class="mx-tableFixed"]
473473
> | Actions | Description |
474474
> | --- | --- |
475-
> | [Microsoft.EventHub](../permissions/analytics.md#microsofteventhub)/namespaces/schemagroups/* | |
475+
> | [Microsoft.EventHub](../permissions/integration.md#microsofteventhub)/namespaces/schemagroups/* | |
476476
> | **NotActions** | |
477477
> | *none* | |
478478
> | **DataActions** | |
479-
> | [Microsoft.EventHub](../permissions/analytics.md#microsofteventhub)/namespaces/schemas/* | |
479+
> | [Microsoft.EventHub](../permissions/integration.md#microsofteventhub)/namespaces/schemas/* | |
480480
> | **NotDataActions** | |
481481
> | *none* | |
482482
@@ -513,11 +513,11 @@ Read and list Schema Registry groups and schemas.
513513
> [!div class="mx-tableFixed"]
514514
> | Actions | Description |
515515
> | --- | --- |
516-
> | [Microsoft.EventHub](../permissions/analytics.md#microsofteventhub)/namespaces/schemagroups/read | Get list of SchemaGroup Resource Descriptions |
516+
> | [Microsoft.EventHub](../permissions/integration.md#microsofteventhub)/namespaces/schemagroups/read | Get list of SchemaGroup Resource Descriptions |
517517
> | **NotActions** | |
518518
> | *none* | |
519519
> | **DataActions** | |
520-
> | [Microsoft.EventHub](../permissions/analytics.md#microsofteventhub)/namespaces/schemas/read | Retrieve schemas |
520+
> | [Microsoft.EventHub](../permissions/integration.md#microsofteventhub)/namespaces/schemas/read | Retrieve schemas |
521521
> | **NotDataActions** | |
522522
> | *none* | |
523523
@@ -554,10 +554,10 @@ Lets you perform query testing without creating a stream analytics job first
554554
> [!div class="mx-tableFixed"]
555555
> | Actions | Description |
556556
> | --- | --- |
557-
> | [Microsoft.StreamAnalytics](../permissions/analytics.md#microsoftstreamanalytics)/locations/TestQuery/action | Test Query for Stream Analytics Resource Provider |
558-
> | [Microsoft.StreamAnalytics](../permissions/analytics.md#microsoftstreamanalytics)/locations/OperationResults/read | Read Stream Analytics Operation Result |
559-
> | [Microsoft.StreamAnalytics](../permissions/analytics.md#microsoftstreamanalytics)/locations/SampleInput/action | Sample Input for Stream Analytics Resource Provider |
560-
> | [Microsoft.StreamAnalytics](../permissions/analytics.md#microsoftstreamanalytics)/locations/CompileQuery/action | Compile Query for Stream Analytics Resource Provider |
557+
> | [Microsoft.StreamAnalytics](../permissions/internet-of-things.md#microsoftstreamanalytics)/locations/TestQuery/action | Test Query for Stream Analytics Resource Provider |
558+
> | [Microsoft.StreamAnalytics](../permissions/internet-of-things.md#microsoftstreamanalytics)/locations/OperationResults/read | Read Stream Analytics Operation Result |
559+
> | [Microsoft.StreamAnalytics](../permissions/internet-of-things.md#microsoftstreamanalytics)/locations/SampleInput/action | Sample Input for Stream Analytics Resource Provider |
560+
> | [Microsoft.StreamAnalytics](../permissions/internet-of-things.md#microsoftstreamanalytics)/locations/CompileQuery/action | Compile Query for Stream Analytics Resource Provider |
561561
> | **NotActions** | |
562562
> | *none* | |
563563
> | **DataActions** | |

0 commit comments

Comments
 (0)