Inbyggda Azure-roller för hantering och styrning

I den här artikeln visas de inbyggda Azure-rollerna i kategorin Hantering och styrning.

Automation-deltagare

Hantera Azure Automation-resurser och andra resurser med hjälp av Azure Automation.

Läs mer

Åtgärder beskrivning
Microsoft.Automation/automationAccounts/*
Microsoft.Authorization/*/read Läsa roller och rolltilldelningar
Microsoft.Resources/deployments/* Skapa och hantera en distribution
Microsoft.Resources/subscriptions/resourceGroups/read Hämtar eller listar resursgrupper.
Microsoft.Support/* Skapa och uppdatera ett supportärende
Microsoft.Insights/ActionGroups/*
Microsoft.Insights/ActivityLogAlerts/*
Microsoft.Insights/MetricAlerts/*
Microsoft.Insights/ScheduledQueryRules/*
Microsoft.Insights/diagnostic Inställningar/* Skapar, uppdaterar eller läser diagnostikinställningen för Analysis Server
Microsoft.OperationalInsights/workspaces/sharedKeys/action Hämtar de delade nycklarna för arbetsytan. Dessa nycklar används för att ansluta Microsoft Operational Insights-agenter till arbetsytan.
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Manage azure automation resources and other resources using azure automation.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/f353d9bd-d4a6-484e-a77a-8050b599b867",
  "name": "f353d9bd-d4a6-484e-a77a-8050b599b867",
  "permissions": [
    {
      "actions": [
        "Microsoft.Automation/automationAccounts/*",
        "Microsoft.Authorization/*/read",
        "Microsoft.Resources/deployments/*",
        "Microsoft.Resources/subscriptions/resourceGroups/read",
        "Microsoft.Support/*",
        "Microsoft.Insights/ActionGroups/*",
        "Microsoft.Insights/ActivityLogAlerts/*",
        "Microsoft.Insights/MetricAlerts/*",
        "Microsoft.Insights/ScheduledQueryRules/*",
        "Microsoft.Insights/diagnosticSettings/*",
        "Microsoft.OperationalInsights/workspaces/sharedKeys/action"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Automation Contributor",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Automation Job Operator

Skapa och hantera jobb med Automation Runbooks.

Läs mer

Åtgärder beskrivning
Microsoft.Authorization/*/read Läsa roller och rolltilldelningar
Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/read Läser en Hybrid Runbook Worker-grupp
Microsoft.Automation/automationAccounts/jobs/read Hämtar ett Azure Automation-jobb
Microsoft.Automation/automationAccounts/jobs/resume/action Återupptar ett Azure Automation-jobb
Microsoft.Automation/automationAccounts/jobs/stop/action Stoppar ett Azure Automation-jobb
Microsoft.Automation/automationAccounts/jobs/streams/read Hämtar en Azure Automation-jobbström
Microsoft.Automation/automationAccounts/jobs/suspend/action Pausar ett Azure Automation-jobb
Microsoft.Automation/automationAccounts/jobs/write Skapar ett Azure Automation-jobb
Microsoft.Automation/automationAccounts/jobs/output/read Hämtar utdata för ett jobb
Microsoft.Insights/alertRules/* Skapa och hantera en klassisk måttavisering
Microsoft.Resources/deployments/* Skapa och hantera en distribution
Microsoft.Resources/subscriptions/resourceGroups/read Hämtar eller listar resursgrupper.
Microsoft.Support/* Skapa och uppdatera ett supportärende
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Create and Manage Jobs using Automation Runbooks.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/4fe576fe-1146-4730-92eb-48519fa6bf9f",
  "name": "4fe576fe-1146-4730-92eb-48519fa6bf9f",
  "permissions": [
    {
      "actions": [
        "Microsoft.Authorization/*/read",
        "Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/read",
        "Microsoft.Automation/automationAccounts/jobs/read",
        "Microsoft.Automation/automationAccounts/jobs/resume/action",
        "Microsoft.Automation/automationAccounts/jobs/stop/action",
        "Microsoft.Automation/automationAccounts/jobs/streams/read",
        "Microsoft.Automation/automationAccounts/jobs/suspend/action",
        "Microsoft.Automation/automationAccounts/jobs/write",
        "Microsoft.Automation/automationAccounts/jobs/output/read",
        "Microsoft.Insights/alertRules/*",
        "Microsoft.Resources/deployments/*",
        "Microsoft.Resources/subscriptions/resourceGroups/read",
        "Microsoft.Support/*"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Automation Job Operator",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Automation-operatör

Automation-operatörer kan starta, stoppa, pausa och återuppta jobb

Läs mer

Åtgärder beskrivning
Microsoft.Authorization/*/read Läsa roller och rolltilldelningar
Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/read Läser en Hybrid Runbook Worker-grupp
Microsoft.Automation/automationAccounts/jobs/read Hämtar ett Azure Automation-jobb
Microsoft.Automation/automationAccounts/jobs/resume/action Återupptar ett Azure Automation-jobb
Microsoft.Automation/automationAccounts/jobs/stop/action Stoppar ett Azure Automation-jobb
Microsoft.Automation/automationAccounts/jobs/streams/read Hämtar en Azure Automation-jobbström
Microsoft.Automation/automationAccounts/jobs/suspend/action Pausar ett Azure Automation-jobb
Microsoft.Automation/automationAccounts/jobs/write Skapar ett Azure Automation-jobb
Microsoft.Automation/automationAccounts/jobSchedules/read Hämtar ett Azure Automation-jobbschema
Microsoft.Automation/automationAccounts/jobSchedules/write Skapar ett Azure Automation-jobbschema
Microsoft.Automation/automationAccounts/linkedWorkspace/read Hämtar arbetsytan länkad till automationskontot
Microsoft.Automation/automationAccounts/read Hämtar ett Azure Automation-konto
Microsoft.Automation/automationAccounts/runbooks/read Hämtar en Azure Automation-runbook
Microsoft.Automation/automationAccounts/schedules/read Hämtar en Azure Automation-schematillgång
Microsoft.Automation/automationAccounts/schedules/write Skapar eller uppdaterar en Azure Automation-schematillgång
Microsoft.Insights/alertRules/* Skapa och hantera en klassisk måttavisering
Microsoft.ResourceHealth/availabilityStatuses/read Hämtar tillgänglighetsstatusar för alla resurser i det angivna omfånget
Microsoft.Resources/deployments/* Skapa och hantera en distribution
Microsoft.Automation/automationAccounts/jobs/output/read Hämtar utdata för ett jobb
Microsoft.Resources/subscriptions/resourceGroups/read Hämtar eller listar resursgrupper.
Microsoft.Support/* Skapa och uppdatera ett supportärende
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Automation Operators are able to start, stop, suspend, and resume jobs",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/d3881f73-407a-4167-8283-e981cbba0404",
  "name": "d3881f73-407a-4167-8283-e981cbba0404",
  "permissions": [
    {
      "actions": [
        "Microsoft.Authorization/*/read",
        "Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/read",
        "Microsoft.Automation/automationAccounts/jobs/read",
        "Microsoft.Automation/automationAccounts/jobs/resume/action",
        "Microsoft.Automation/automationAccounts/jobs/stop/action",
        "Microsoft.Automation/automationAccounts/jobs/streams/read",
        "Microsoft.Automation/automationAccounts/jobs/suspend/action",
        "Microsoft.Automation/automationAccounts/jobs/write",
        "Microsoft.Automation/automationAccounts/jobSchedules/read",
        "Microsoft.Automation/automationAccounts/jobSchedules/write",
        "Microsoft.Automation/automationAccounts/linkedWorkspace/read",
        "Microsoft.Automation/automationAccounts/read",
        "Microsoft.Automation/automationAccounts/runbooks/read",
        "Microsoft.Automation/automationAccounts/schedules/read",
        "Microsoft.Automation/automationAccounts/schedules/write",
        "Microsoft.Insights/alertRules/*",
        "Microsoft.ResourceHealth/availabilityStatuses/read",
        "Microsoft.Resources/deployments/*",
        "Microsoft.Automation/automationAccounts/jobs/output/read",
        "Microsoft.Resources/subscriptions/resourceGroups/read",
        "Microsoft.Support/*"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Automation Operator",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Runbook-operatör för Automation

Läs Runbook-egenskaper – för att kunna skapa jobb för runbooken.

Läs mer

Åtgärder beskrivning
Microsoft.Authorization/*/read Läsa roller och rolltilldelningar
Microsoft.Automation/automationAccounts/runbooks/read Hämtar en Azure Automation-runbook
Microsoft.Insights/alertRules/* Skapa och hantera en klassisk måttavisering
Microsoft.Resources/deployments/* Skapa och hantera en distribution
Microsoft.Resources/subscriptions/resourceGroups/read Hämtar eller listar resursgrupper.
Microsoft.Support/* Skapa och uppdatera ett supportärende
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Read Runbook properties - to be able to create Jobs of the runbook.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/5fb5aef8-1081-4b8e-bb16-9d5d0385bab5",
  "name": "5fb5aef8-1081-4b8e-bb16-9d5d0385bab5",
  "permissions": [
    {
      "actions": [
        "Microsoft.Authorization/*/read",
        "Microsoft.Automation/automationAccounts/runbooks/read",
        "Microsoft.Insights/alertRules/*",
        "Microsoft.Resources/deployments/*",
        "Microsoft.Resources/subscriptions/resourceGroups/read",
        "Microsoft.Support/*"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Automation Runbook Operator",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Azure Anslut ed Machine Onboarding

Kan registrera Azure Anslut ed Machines.

Läs mer

Åtgärder beskrivning
Microsoft.HybridCompute/machines/read Läsa alla Azure Arc-datorer
Microsoft.HybridCompute/machines/write Skriver en Azure Arc-dator
Microsoft.HybridCompute/privateLinkScopes/read Läs alla Azure Arc privateLinkScopes
Microsoft.GuestConfiguration/guestConfigurationAssignments/read Hämta gästkonfigurationstilldelning.
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Can onboard Azure Connected Machines.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/b64e21ea-ac4e-4cdf-9dc9-5b892992bee7",
  "name": "b64e21ea-ac4e-4cdf-9dc9-5b892992bee7",
  "permissions": [
    {
      "actions": [
        "Microsoft.HybridCompute/machines/read",
        "Microsoft.HybridCompute/machines/write",
        "Microsoft.HybridCompute/privateLinkScopes/read",
        "Microsoft.GuestConfiguration/guestConfigurationAssignments/read"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Azure Connected Machine Onboarding",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Azure Connected Machine resursadministratör

Kan läsa, skriva, ta bort och publicera azure-Anslut datorer igen.

Läs mer

Åtgärder beskrivning
Microsoft.HybridCompute/machines/read Läsa alla Azure Arc-datorer
Microsoft.HybridCompute/machines/write Skriver en Azure Arc-dator
Microsoft.HybridCompute/machines/delete Tar bort en Azure Arc-dator
Microsoft.HybridCompute/machines/UpgradeExtensions/action Uppgraderar tillägg på Azure Arc-datorer
Microsoft.HybridCompute/machines/extensions/read Läser alla Azure Arc-tillägg
Microsoft.HybridCompute/machines/extensions/write Installerar eller Uppdateringar ett Azure Arc-tillägg
Microsoft.HybridCompute/machines/extensions/delete Tar bort ett Azure Arc-tillägg
Microsoft.HybridCompute/privateLinkScopes/*
Microsoft.HybridCompute/*/read
Microsoft.Resources/deployments/* Skapa och hantera en distribution
Microsoft.HybridCompute/licenses/write Installerar eller Uppdateringar en Azure Arc-licens
Microsoft.HybridCompute/licenses/delete Tar bort en Azure Arc-licens
Microsoft.HybridCompute/machines/licenseProfiles/read Läser alla Azure Arc-licensprofiler
Microsoft.HybridCompute/machines/licenseProfiles/write Installerar eller Uppdateringar en Azure Arc-licensProfiler
Microsoft.HybridCompute/machines/licenseProfiles/delete Tar bort en Azure Arc-licensProfiler
Microsoft.HybridCompute/machines/runCommands/read Läser alla Azure Arc-runcommands
Microsoft.HybridCompute/machines/runCommands/write Installerar eller Uppdateringar en Azure Arc-runcommands
Microsoft.HybridCompute/machines/runCommands/delete Tar bort en Azure Arc-runcommands
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Can read, write, delete and re-onboard Azure Connected Machines.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/cd570a14-e51a-42ad-bac8-bafd67325302",
  "name": "cd570a14-e51a-42ad-bac8-bafd67325302",
  "permissions": [
    {
      "actions": [
        "Microsoft.HybridCompute/machines/read",
        "Microsoft.HybridCompute/machines/write",
        "Microsoft.HybridCompute/machines/delete",
        "Microsoft.HybridCompute/machines/UpgradeExtensions/action",
        "Microsoft.HybridCompute/machines/extensions/read",
        "Microsoft.HybridCompute/machines/extensions/write",
        "Microsoft.HybridCompute/machines/extensions/delete",
        "Microsoft.HybridCompute/privateLinkScopes/*",
        "Microsoft.HybridCompute/*/read",
        "Microsoft.Resources/deployments/*",
        "Microsoft.HybridCompute/licenses/write",
        "Microsoft.HybridCompute/licenses/delete",
        "Microsoft.HybridCompute/machines/licenseProfiles/read",
        "Microsoft.HybridCompute/machines/licenseProfiles/write",
        "Microsoft.HybridCompute/machines/licenseProfiles/delete",
        "Microsoft.HybridCompute/machines/runCommands/read",
        "Microsoft.HybridCompute/machines/runCommands/write",
        "Microsoft.HybridCompute/machines/runCommands/delete"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Azure Connected Machine Resource Administrator",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Azure Anslut ed Machine Resource Manager

Anpassad roll för AzureStackHCI RP för att hantera hybriddatorer och hybridanslutningsslutpunkter i en resursgrupp

Läs mer

Åtgärder beskrivning
Microsoft.Hybrid Anslut ivity/endpoints/read Hämtar slutpunkten till resursen.
Microsoft.Hybrid Anslut ivity/endpoints/write Uppdatera slutpunkten till målresursen.
Microsoft.Hybrid Anslut ivity/endpoints/serviceConfigurations/read Hämtar information om tjänsten till resursen.
Microsoft.Hybrid Anslut ivity/endpoints/serviceConfigurations/write Uppdatera tjänstinformationen i tjänstkonfigurationerna för målresursen.
Microsoft.HybridCompute/machines/read Läsa alla Azure Arc-datorer
Microsoft.HybridCompute/machines/write Skriver en Azure Arc-dator
Microsoft.HybridCompute/machines/delete Tar bort en Azure Arc-dator
Microsoft.HybridCompute/machines/extensions/read Läser alla Azure Arc-tillägg
Microsoft.HybridCompute/machines/extensions/write Installerar eller Uppdateringar ett Azure Arc-tillägg
Microsoft.HybridCompute/machines/extensions/delete Tar bort ett Azure Arc-tillägg
Microsoft.HybridCompute/*/read
Microsoft.HybridCompute/machines/UpgradeExtensions/action Uppgraderar tillägg på Azure Arc-datorer
Microsoft.HybridCompute/machines/licenseProfiles/read Läser alla Azure Arc-licensprofiler
Microsoft.HybridCompute/machines/licenseProfiles/write Installerar eller Uppdateringar en Azure Arc-licensProfiler
Microsoft.HybridCompute/machines/licenseProfiles/delete Tar bort en Azure Arc-licensProfiler
Microsoft.GuestConfiguration/guestConfigurationAssignments/read Hämta gästkonfigurationstilldelning.
Microsoft.GuestConfiguration/guestConfigurationAssignments/*/read
Microsoft.GuestConfiguration/guestConfigurationAssignments/write Skapa ny gästkonfigurationstilldelning.
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Custom Role for AzureStackHCI RP to manage hybrid compute machines and hybrid connectivity endpoints in a resource group",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/f5819b54-e033-4d82-ac66-4fec3cbf3f4c",
  "name": "f5819b54-e033-4d82-ac66-4fec3cbf3f4c",
  "permissions": [
    {
      "actions": [
        "Microsoft.HybridConnectivity/endpoints/read",
        "Microsoft.HybridConnectivity/endpoints/write",
        "Microsoft.HybridConnectivity/endpoints/serviceConfigurations/read",
        "Microsoft.HybridConnectivity/endpoints/serviceConfigurations/write",
        "Microsoft.HybridCompute/machines/read",
        "Microsoft.HybridCompute/machines/write",
        "Microsoft.HybridCompute/machines/delete",
        "Microsoft.HybridCompute/machines/extensions/read",
        "Microsoft.HybridCompute/machines/extensions/write",
        "Microsoft.HybridCompute/machines/extensions/delete",
        "Microsoft.HybridCompute/*/read",
        "Microsoft.HybridCompute/machines/UpgradeExtensions/action",
        "Microsoft.HybridCompute/machines/licenseProfiles/read",
        "Microsoft.HybridCompute/machines/licenseProfiles/write",
        "Microsoft.HybridCompute/machines/licenseProfiles/delete",
        "Microsoft.GuestConfiguration/guestConfigurationAssignments/read",
        "Microsoft.GuestConfiguration/guestConfigurationAssignments/*/read",
        "Microsoft.GuestConfiguration/guestConfigurationAssignments/write"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Azure Connected Machine Resource Manager",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Faktureringsläsare

Tillåter läsåtkomst till faktureringsdata

Läs mer

Åtgärder beskrivning
Microsoft.Authorization/*/read Läsa roller och rolltilldelningar
Microsoft.Billing/*/read Läs faktureringsinformation
Microsoft.Commerce/*/read
Microsoft.Consumption/*/read
Microsoft.Management/managementGroups/read Lista hanteringsgrupper för den autentiserade användaren.
Microsoft.CostManagement/*/read
Microsoft.Support/* Skapa och uppdatera ett supportärende
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Allows read access to billing data",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/fa23ad8b-c56e-40d8-ac0c-ce449e1d2c64",
  "name": "fa23ad8b-c56e-40d8-ac0c-ce449e1d2c64",
  "permissions": [
    {
      "actions": [
        "Microsoft.Authorization/*/read",
        "Microsoft.Billing/*/read",
        "Microsoft.Commerce/*/read",
        "Microsoft.Consumption/*/read",
        "Microsoft.Management/managementGroups/read",
        "Microsoft.CostManagement/*/read",
        "Microsoft.Support/*"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Billing Reader",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Skissdeltagare

Kan hantera skissdefinitioner, men inte tilldela dem.

Läs mer

Åtgärder beskrivning
Microsoft.Authorization/*/read Läsa roller och rolltilldelningar
Microsoft.Blueprint/blueprints/* Skapa och hantera skissdefinitioner eller skissartefakter.
Microsoft.Resources/subscriptions/resourceGroups/read Hämtar eller listar resursgrupper.
Microsoft.Resources/deployments/* Skapa och hantera en distribution
Microsoft.Support/* Skapa och uppdatera ett supportärende
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Can manage blueprint definitions, but not assign them.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/41077137-e803-4205-871c-5a86e6a753b4",
  "name": "41077137-e803-4205-871c-5a86e6a753b4",
  "permissions": [
    {
      "actions": [
        "Microsoft.Authorization/*/read",
        "Microsoft.Blueprint/blueprints/*",
        "Microsoft.Resources/subscriptions/resourceGroups/read",
        "Microsoft.Resources/deployments/*",
        "Microsoft.Support/*"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Blueprint Contributor",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Skissoperator

Kan tilldela befintliga publicerade skisser, men kan inte skapa nya skisser. Observera att detta endast fungerar om tilldelningen görs med en användartilldelad hanterad identitet.

Läs mer

Åtgärder beskrivning
Microsoft.Authorization/*/read Läsa roller och rolltilldelningar
Microsoft.Blueprint/blueprintAssignments/* Skapa och hantera skisstilldelningar.
Microsoft.Resources/subscriptions/resourceGroups/read Hämtar eller listar resursgrupper.
Microsoft.Resources/deployments/* Skapa och hantera en distribution
Microsoft.Support/* Skapa och uppdatera ett supportärende
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Can assign existing published blueprints, but cannot create new blueprints. NOTE: this only works if the assignment is done with a user-assigned managed identity.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/437d2ced-4a38-4302-8479-ed2bcb43d090",
  "name": "437d2ced-4a38-4302-8479-ed2bcb43d090",
  "permissions": [
    {
      "actions": [
        "Microsoft.Authorization/*/read",
        "Microsoft.Blueprint/blueprintAssignments/*",
        "Microsoft.Resources/subscriptions/resourceGroups/read",
        "Microsoft.Resources/deployments/*",
        "Microsoft.Support/*"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Blueprint Operator",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Läsare för koldioxidoptimering

Tillåt läsåtkomst till Azure Carbon Optimization-data

Läs mer

Åtgärder beskrivning
Microsoft.Carbon/carbonEmissionReports/action API för rapporter om koldioxidutsläpp
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Allow read access to Azure Carbon Optimization data",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/fa0d39e6-28e5-40cf-8521-1eb320653a4c",
  "name": "fa0d39e6-28e5-40cf-8521-1eb320653a4c",
  "permissions": [
    {
      "actions": [
        "Microsoft.Carbon/carbonEmissionReports/action"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Carbon Optimization Reader",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Cost Management-deltagare

Kan visa kostnader och hantera kostnadskonfiguration (t.ex. budgetar, exporter)

Läs mer

Åtgärder beskrivning
Microsoft.Consumption/*
Microsoft.CostManagement/*
Microsoft.Billing/billingPeriods/read
Microsoft.Resources/subscriptions/read Hämtar listan över prenumerationer.
Microsoft.Resources/subscriptions/resourceGroups/read Hämtar eller listar resursgrupper.
Microsoft.Support/* Skapa och uppdatera ett supportärende
Microsoft.Advisor/configurations/read Hämta konfigurationer
Microsoft.Advisor/recommendations/read Läsrekommendationer
Microsoft.Management/managementGroups/read Lista hanteringsgrupper för den autentiserade användaren.
Microsoft.Billing/billingProperty/read Hämtar faktureringsegenskaperna för en prenumeration
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Can view costs and manage cost configuration (e.g. budgets, exports)",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/434105ed-43f6-45c7-a02f-909b2ba83430",
  "name": "434105ed-43f6-45c7-a02f-909b2ba83430",
  "permissions": [
    {
      "actions": [
        "Microsoft.Consumption/*",
        "Microsoft.CostManagement/*",
        "Microsoft.Billing/billingPeriods/read",
        "Microsoft.Resources/subscriptions/read",
        "Microsoft.Resources/subscriptions/resourceGroups/read",
        "Microsoft.Support/*",
        "Microsoft.Advisor/configurations/read",
        "Microsoft.Advisor/recommendations/read",
        "Microsoft.Management/managementGroups/read",
        "Microsoft.Billing/billingProperty/read"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Cost Management Contributor",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Cost Management-läsare

Kan visa kostnadsdata och konfiguration (t.ex. budgetar, exporter)

Läs mer

Åtgärder beskrivning
Microsoft.Consumption/*/read
Microsoft.CostManagement/*/read
Microsoft.Billing/billingPeriods/read
Microsoft.Resources/subscriptions/read Hämtar listan över prenumerationer.
Microsoft.Resources/subscriptions/resourceGroups/read Hämtar eller listar resursgrupper.
Microsoft.Support/* Skapa och uppdatera ett supportärende
Microsoft.Advisor/configurations/read Hämta konfigurationer
Microsoft.Advisor/recommendations/read Läsrekommendationer
Microsoft.Management/managementGroups/read Lista hanteringsgrupper för den autentiserade användaren.
Microsoft.Billing/billingProperty/read Hämtar faktureringsegenskaperna för en prenumeration
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Can view cost data and configuration (e.g. budgets, exports)",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/72fafb9e-0641-4937-9268-a91bfd8191a3",
  "name": "72fafb9e-0641-4937-9268-a91bfd8191a3",
  "permissions": [
    {
      "actions": [
        "Microsoft.Consumption/*/read",
        "Microsoft.CostManagement/*/read",
        "Microsoft.Billing/billingPeriods/read",
        "Microsoft.Resources/subscriptions/read",
        "Microsoft.Resources/subscriptions/resourceGroups/read",
        "Microsoft.Support/*",
        "Microsoft.Advisor/configurations/read",
        "Microsoft.Advisor/recommendations/read",
        "Microsoft.Management/managementGroups/read",
        "Microsoft.Billing/billingProperty/read"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Cost Management Reader",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Hierarki Inställningar administratör

Tillåter användare att redigera och ta bort hierarki Inställningar

Åtgärder beskrivning
Microsoft.Management/managementGroups/settings/write Skapar eller uppdaterar hierarkiinställningar för hanteringsgrupper.
Microsoft.Management/managementGroups/settings/delete Tar bort inställningar för hanteringsgruppshierarki.
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Allows users to edit and delete Hierarchy Settings",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/350f8d15-c687-4448-8ae1-157740a3936d",
  "name": "350f8d15-c687-4448-8ae1-157740a3936d",
  "permissions": [
    {
      "actions": [
        "Microsoft.Management/managementGroups/settings/write",
        "Microsoft.Management/managementGroups/settings/delete"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Hierarchy Settings Administrator",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Deltagarroll för hanterat program

Tillåter att hanterade programresurser skapas.

Åtgärder beskrivning
*/read Läsa resurser av alla typer, förutom hemligheter.
Microsoft.Solutions/applications/*
Microsoft.Solutions/register/action Registrera prenumerationen för Microsoft.Solutions
Microsoft.Resources/subscriptions/resourceGroups/*
Microsoft.Resources/deployments/* Skapa och hantera en distribution
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Allows for creating managed application resources.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/641177b8-a67a-45b9-a033-47bc880bb21e",
  "name": "641177b8-a67a-45b9-a033-47bc880bb21e",
  "permissions": [
    {
      "actions": [
        "*/read",
        "Microsoft.Solutions/applications/*",
        "Microsoft.Solutions/register/action",
        "Microsoft.Resources/subscriptions/resourceGroups/*",
        "Microsoft.Resources/deployments/*"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Managed Application Contributor Role",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Hanterad programoperatorroll

Gör att du kan läsa och utföra åtgärder på hanterade programresurser

Åtgärder beskrivning
*/read Läsa resurser av alla typer, förutom hemligheter.
Microsoft.Solutions/applications/read Visar en lista över alla program i en prenumeration.
Microsoft.Solutions/*/action
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Lets you read and perform actions on Managed Application resources",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/c7393b34-138c-406f-901b-d8cf2b17e6ae",
  "name": "c7393b34-138c-406f-901b-d8cf2b17e6ae",
  "permissions": [
    {
      "actions": [
        "*/read",
        "Microsoft.Solutions/applications/read",
        "Microsoft.Solutions/*/action"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Managed Application Operator Role",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Läsare för hanterade program

Låter dig läsa resurser i en hanterad app och begära JIT-åtkomst.

Åtgärder beskrivning
*/read Läsa resurser av alla typer, förutom hemligheter.
Microsoft.Resources/deployments/* Skapa och hantera en distribution
Microsoft.Solutions/jitRequests/*
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Lets you read resources in a managed app and request JIT access.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/b9331d33-8a36-4f8c-b097-4f54124fdb44",
  "name": "b9331d33-8a36-4f8c-b097-4f54124fdb44",
  "permissions": [
    {
      "actions": [
        "*/read",
        "Microsoft.Resources/deployments/*",
        "Microsoft.Solutions/jitRequests/*"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Managed Applications Reader",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Ta bort roll för registreringstilldelning för hanterade tjänster

Med borttagningsrollen för registrering av hanterade tjänster kan de hantera klientanvändare ta bort den registreringstilldelning som tilldelats deras klientorganisation.

Läs mer

Åtgärder beskrivning
Microsoft.ManagedServices/registrationAssignments/read Hämtar en lista över registreringstilldelningar för Managed Services.
Microsoft.ManagedServices/registrationAssignments/delete Tar bort registreringstilldelning för Managed Services.
Microsoft.ManagedServices/operationStatuses/read Läser åtgärdsstatusen för resursen.
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Managed Services Registration Assignment Delete Role allows the managing tenant users to delete the registration assignment assigned to their tenant.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/91c1777a-f3dc-4fae-b103-61d183457e46",
  "name": "91c1777a-f3dc-4fae-b103-61d183457e46",
  "permissions": [
    {
      "actions": [
        "Microsoft.ManagedServices/registrationAssignments/read",
        "Microsoft.ManagedServices/registrationAssignments/delete",
        "Microsoft.ManagedServices/operationStatuses/read"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Managed Services Registration assignment Delete Role",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Deltagare i hanteringsgrupp

Deltagarroll för hanteringsgrupp

Läs mer

Åtgärder beskrivning
Microsoft.Management/managementGroups/delete Ta bort hanteringsgrupp.
Microsoft.Management/managementGroups/read Lista hanteringsgrupper för den autentiserade användaren.
Microsoft.Management/managementGroups/subscriptions/delete Koppla från prenumerationen från hanteringsgruppen.
Microsoft.Management/managementGroups/subscriptions/write Associerar en befintlig prenumeration med hanteringsgruppen.
Microsoft.Management/managementGroups/write Skapa eller uppdatera en hanteringsgrupp.
Microsoft.Management/managementGroups/subscriptions/read Visar en lista över prenumerationer under den angivna hanteringsgruppen.
Microsoft.Authorization/*/read Läsa roller och rolltilldelningar
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Management Group Contributor Role",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/5d58bcaf-24a5-4b20-bdb6-eed9f69fbe4c",
  "name": "5d58bcaf-24a5-4b20-bdb6-eed9f69fbe4c",
  "permissions": [
    {
      "actions": [
        "Microsoft.Management/managementGroups/delete",
        "Microsoft.Management/managementGroups/read",
        "Microsoft.Management/managementGroups/subscriptions/delete",
        "Microsoft.Management/managementGroups/subscriptions/write",
        "Microsoft.Management/managementGroups/write",
        "Microsoft.Management/managementGroups/subscriptions/read",
        "Microsoft.Authorization/*/read"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Management Group Contributor",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Hanteringsgruppsläsare

Läsarroll för hanteringsgrupp

Åtgärder beskrivning
Microsoft.Management/managementGroups/read Lista hanteringsgrupper för den autentiserade användaren.
Microsoft.Management/managementGroups/subscriptions/read Visar en lista över prenumerationer under den angivna hanteringsgruppen.
Microsoft.Authorization/*/read Läsa roller och rolltilldelningar
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Management Group Reader Role",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/ac63b705-f282-497d-ac71-919bf39d939d",
  "name": "ac63b705-f282-497d-ac71-919bf39d939d",
  "permissions": [
    {
      "actions": [
        "Microsoft.Management/managementGroups/read",
        "Microsoft.Management/managementGroups/subscriptions/read",
        "Microsoft.Authorization/*/read"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Management Group Reader",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Ny relik-APM-kontodeltagare

Gör att du kan hantera konton och program för hantering av nya relikprogramsprestanda, men inte åtkomst till dem.

Åtgärder beskrivning
Microsoft.Authorization/*/read Läsa roller och rolltilldelningar
Microsoft.Insights/alertRules/* Skapa och hantera en klassisk måttavisering
Microsoft.ResourceHealth/availabilityStatuses/read Hämtar tillgänglighetsstatusar för alla resurser i det angivna omfånget
Microsoft.Resources/deployments/* Skapa och hantera en distribution
Microsoft.Resources/subscriptions/resourceGroups/read Hämtar eller listar resursgrupper.
Microsoft.Support/* Skapa och uppdatera ett supportärende
NewRelic.APM/accounts/*
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Lets you manage New Relic Application Performance Management accounts and applications, but not access to them.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/5d28c62d-5b37-4476-8438-e587778df237",
  "name": "5d28c62d-5b37-4476-8438-e587778df237",
  "permissions": [
    {
      "actions": [
        "Microsoft.Authorization/*/read",
        "Microsoft.Insights/alertRules/*",
        "Microsoft.ResourceHealth/availabilityStatuses/read",
        "Microsoft.Resources/deployments/*",
        "Microsoft.Resources/subscriptions/resourceGroups/read",
        "Microsoft.Support/*",
        "NewRelic.APM/accounts/*"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "New Relic APM Account Contributor",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Policy Insights Data Writer (förhandsversion)

Tillåter läsåtkomst till resursprinciper och skrivåtkomst till resurskomponentprinciphändelser.

Läs mer

Åtgärder beskrivning
Microsoft.Authorization/policyassignments/read Hämta information om en principtilldelning.
Microsoft.Authorization/policydefinitions/read Hämta information om en principdefinition.
Microsoft.Authorization/policyexemptions/read Få information om ett principundantag.
Microsoft.Authorization/policysetdefinitions/read Hämta information om en principuppsättningsdefinition.
NotActions
ingen
DataActions
Microsoft.PolicyInsights/checkDataPolicyCompliance/action Kontrollera efterlevnadsstatusen för en viss komponent mot dataprinciper.
Microsoft.PolicyInsights/policyEvents/logDataEvents/action Logga resurskomponentens principhändelser.
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Allows read access to resource policies and write access to resource component policy events.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/66bb4e9e-b016-4a94-8249-4c0511c2be84",
  "name": "66bb4e9e-b016-4a94-8249-4c0511c2be84",
  "permissions": [
    {
      "actions": [
        "Microsoft.Authorization/policyassignments/read",
        "Microsoft.Authorization/policydefinitions/read",
        "Microsoft.Authorization/policyexemptions/read",
        "Microsoft.Authorization/policysetdefinitions/read"
      ],
      "notActions": [],
      "dataActions": [
        "Microsoft.PolicyInsights/checkDataPolicyCompliance/action",
        "Microsoft.PolicyInsights/policyEvents/logDataEvents/action"
      ],
      "notDataActions": []
    }
  ],
  "roleName": "Policy Insights Data Writer (Preview)",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Operator för kvotbegäran

Läs och skapa kvotbegäranden, hämta status för kvotbegäran och skapa supportärenden.

Läs mer

Åtgärder beskrivning
Microsoft.Capacity/resourceProviders/locations/serviceLimits/read Hämta den aktuella tjänstgränsen eller kvoten för den angivna resursen och platsen
Microsoft.Capacity/resourceProviders/locations/serviceLimits/write Skapa tjänstgräns eller kvot för den angivna resursen och platsen
Microsoft.Capacity/resourceProviders/locations/serviceLimitsRequests/read Hämta en tjänstgränsbegäran för den angivna resursen och platsen
Microsoft.Capacity/register/action Registrerar kapacitetsresursprovidern och gör det möjligt att skapa kapacitetsresurser.
Microsoft.Quota/usages/read Hämta användning för resursprovidrar
Microsoft.Quota/quotas/read Hämta den aktuella tjänstgränsen eller kvoten för den angivna resursen
Microsoft.Quota/quotas/write Skapar tjänstgränsen eller kvotbegäran för den angivna resursen
Microsoft.Quota/quotaRequests/read Hämta en tjänstgränsbegäran för den angivna resursen
Microsoft.Quota/register/action Registrera prenumerationen med Microsoft.Quota Resource Provider
Microsoft.Authorization/*/read Läsa roller och rolltilldelningar
Microsoft.Insights/alertRules/* Skapa och hantera en klassisk måttavisering
Microsoft.Resources/deployments/* Skapa och hantera en distribution
Microsoft.Resources/subscriptions/resourceGroups/read Hämtar eller listar resursgrupper.
Microsoft.Support/* Skapa och uppdatera ett supportärende
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Read and create quota requests, get quota request status, and create support tickets.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/0e5f05e5-9ab9-446b-b98d-1e2157c94125",
  "name": "0e5f05e5-9ab9-446b-b98d-1e2157c94125",
  "permissions": [
    {
      "actions": [
        "Microsoft.Capacity/resourceProviders/locations/serviceLimits/read",
        "Microsoft.Capacity/resourceProviders/locations/serviceLimits/write",
        "Microsoft.Capacity/resourceProviders/locations/serviceLimitsRequests/read",
        "Microsoft.Capacity/register/action",
        "Microsoft.Quota/usages/read",
        "Microsoft.Quota/quotas/read",
        "Microsoft.Quota/quotas/write",
        "Microsoft.Quota/quotaRequests/read",
        "Microsoft.Quota/register/action",
        "Microsoft.Authorization/*/read",
        "Microsoft.Insights/alertRules/*",
        "Microsoft.Resources/deployments/*",
        "Microsoft.Resources/subscriptions/resourceGroups/read",
        "Microsoft.Support/*"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Quota Request Operator",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Reservationsköpare

Gör att du kan köpa reservationer

Läs mer

Åtgärder beskrivning
Microsoft.Authorization/roleAssignments/read Hämta information om en rolltilldelning.
Microsoft.Capacity/catalogs/read Läsa reservationskatalogen
Microsoft.Capacity/register/action Registrerar kapacitetsresursprovidern och gör det möjligt att skapa kapacitetsresurser.
Microsoft.Compute/register/action Registrerar prenumeration med Microsoft.Compute-resursprovider
Microsoft.Consumption/register/action Registrera dig för förbruknings-RP
Microsoft.Consumption/reservationRecommendationDetails/read Lista information om reservationsrekommendation
Microsoft.Consumption/reservation Rekommendationer/read Lista enskilda eller delade rekommendationer för reserverade instanser för en prenumeration.
Microsoft.Resources/subscriptions/read Hämtar listan över prenumerationer.
Microsoft.Resources/subscriptions/resourceGroups/read Hämtar eller listar resursgrupper.
Microsoft.SQL/registrera/åtgärd Registrerar prenumerationen för Microsoft SQL Database-resursprovidern och gör det möjligt att skapa Microsoft SQL Databases.
Microsoft.Support/supporttickets/write Tillåter att du skapar och uppdaterar ett supportärende
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Lets you purchase reservations",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/f7b75c60-3036-4b75-91c3-6b41c27c1689",
  "name": "f7b75c60-3036-4b75-91c3-6b41c27c1689",
  "permissions": [
    {
      "actions": [
        "Microsoft.Authorization/roleAssignments/read",
        "Microsoft.Capacity/catalogs/read",
        "Microsoft.Capacity/register/action",
        "Microsoft.Compute/register/action",
        "Microsoft.Consumption/register/action",
        "Microsoft.Consumption/reservationRecommendationDetails/read",
        "Microsoft.Consumption/reservationRecommendations/read",
        "Microsoft.Resources/subscriptions/read",
        "Microsoft.Resources/subscriptions/resourceGroups/read",
        "Microsoft.SQL/register/action",
        "Microsoft.Support/supporttickets/write"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Reservation Purchaser",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Reservationsadministratör

Låter en läsa och hantera alla reservationer i en klientorganisation

Läs mer

Åtgärder beskrivning
Microsoft.Capacity/*/read
Microsoft.Capacity/*/action
Microsoft.Capacity/*/write
Microsoft.Authorization/roleAssignments/read Hämta information om en rolltilldelning.
Microsoft.Authorization/roleDefinitions/read Hämta information om en rolldefinition.
Microsoft.Authorization/roleAssignments/write Skapa en rolltilldelning i det angivna omfånget.
Microsoft.Authorization/roleAssignments/delete Ta bort en rolltilldelning i det angivna omfånget.
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/providers/Microsoft.Capacity"
  ],
  "description": "Lets one read and manage all the reservations in a tenant",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/a8889054-8d42-49c9-bc1c-52486c10e7cd",
  "name": "a8889054-8d42-49c9-bc1c-52486c10e7cd",
  "permissions": [
    {
      "actions": [
        "Microsoft.Capacity/*/read",
        "Microsoft.Capacity/*/action",
        "Microsoft.Capacity/*/write",
        "Microsoft.Authorization/roleAssignments/read",
        "Microsoft.Authorization/roleDefinitions/read",
        "Microsoft.Authorization/roleAssignments/write",
        "Microsoft.Authorization/roleAssignments/delete"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Reservations Administrator",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Reservationsläsare

Låter en läsa alla reservationer i en klientorganisation

Läs mer

Åtgärder beskrivning
Microsoft.Capacity/*/read
Microsoft.Authorization/roleAssignments/read Hämta information om en rolltilldelning.
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/providers/Microsoft.Capacity"
  ],
  "description": "Lets one read all the reservations in a tenant",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/582fc458-8989-419f-a480-75249bc5db7e",
  "name": "582fc458-8989-419f-a480-75249bc5db7e",
  "permissions": [
    {
      "actions": [
        "Microsoft.Capacity/*/read",
        "Microsoft.Authorization/roleAssignments/read"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Reservations Reader",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Deltagare för resursprincip

Användare med behörighet att skapa/ändra resursprincip, skapa supportbegäran och läsa resurser/hierarki.

Läs mer

Åtgärder beskrivning
*/read Läsa resurser av alla typer, förutom hemligheter.
Microsoft.Authorization/policyassignments/* Skapa och hantera principtilldelningar
Microsoft.Authorization/policydefinitions/* Skapa och hantera principdefinitioner
Microsoft.Authorization/policyexemptions/* Skapa och hantera principundantag
Microsoft.Authorization/policysetdefinitions/* Skapa och hantera principuppsättningar
Microsoft.PolicyInsights/*
Microsoft.Resources/deployments/* Skapa och hantera en distribution
Microsoft.Support/* Skapa och uppdatera ett supportärende
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Users with rights to create/modify resource policy, create support ticket and read resources/hierarchy.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/36243c78-bf99-498c-9df9-86d9f8d28608",
  "name": "36243c78-bf99-498c-9df9-86d9f8d28608",
  "permissions": [
    {
      "actions": [
        "*/read",
        "Microsoft.Authorization/policyassignments/*",
        "Microsoft.Authorization/policydefinitions/*",
        "Microsoft.Authorization/policyexemptions/*",
        "Microsoft.Authorization/policysetdefinitions/*",
        "Microsoft.PolicyInsights/*",
        "Microsoft.Resources/deployments/*",
        "Microsoft.Support/*"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Resource Policy Contributor",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Schemalagd uppdateringsdeltagare

Ger åtkomst till att hantera underhållskonfigurationer med underhållsomfånget InGuestPatch och motsvarande konfigurationstilldelningar

Läs mer

Åtgärder beskrivning
Microsoft.Maintenance/maintenanceConfigurations/read Läs underhållskonfiguration.
Microsoft.Maintenance/maintenanceConfigurations/write Skapa eller uppdatera underhållskonfigurationen.
Microsoft.Maintenance/maintenanceConfigurations/delete Ta bort underhållskonfigurationen.
Microsoft.Maintenance/configurationAssignments/read Läs underhållskonfigurationstilldelning.
Microsoft.Maintenance/configurationAssignments/write Skapa eller uppdatera underhållskonfigurationstilldelningen.
Microsoft.Maintenance/configurationAssignments/delete Ta bort tilldelning av underhållskonfiguration.
Microsoft.Maintenance/configurationAssignments/maintenanceScope/InGuestPatch/read Läs underhållskonfigurationstilldelning för InGuestPatch-underhållsomfång.
Microsoft.Maintenance/configurationAssignments/maintenanceScope/InGuestPatch/write Skapa eller uppdatera en underhållskonfigurationstilldelning för Underhållsomfånget InGuestPatch.
Microsoft.Maintenance/configurationAssignments/maintenanceScope/InGuestPatch/delete Ta bort underhållskonfigurationstilldelningen för InGuestPatch-underhållsomfånget.
Microsoft.Maintenance/maintenanceConfigurations/maintenanceScope/InGuestPatch/read Läs underhållskonfiguration för Underhållsomfånget InGuestPatch.
Microsoft.Maintenance/maintenanceConfigurations/maintenanceScope/InGuestPatch/write Skapa eller uppdatera en underhållskonfiguration för underhållsomfånget InGuestPatch.
Microsoft.Maintenance/maintenanceConfigurations/maintenanceScope/InGuestPatch/delete Ta bort underhållskonfigurationen för underhållsomfånget InGuestPatch.
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Provides access to manage maintenance configurations with maintenance scope InGuestPatch and corresponding configuration assignments",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/cd08ab90-6b14-449c-ad9a-8f8e549482c6",
  "name": "cd08ab90-6b14-449c-ad9a-8f8e549482c6",
  "permissions": [
    {
      "actions": [
        "Microsoft.Maintenance/maintenanceConfigurations/read",
        "Microsoft.Maintenance/maintenanceConfigurations/write",
        "Microsoft.Maintenance/maintenanceConfigurations/delete",
        "Microsoft.Maintenance/configurationAssignments/read",
        "Microsoft.Maintenance/configurationAssignments/write",
        "Microsoft.Maintenance/configurationAssignments/delete",
        "Microsoft.Maintenance/configurationAssignments/maintenanceScope/InGuestPatch/read",
        "Microsoft.Maintenance/configurationAssignments/maintenanceScope/InGuestPatch/write",
        "Microsoft.Maintenance/configurationAssignments/maintenanceScope/InGuestPatch/delete",
        "Microsoft.Maintenance/maintenanceConfigurations/maintenanceScope/InGuestPatch/read",
        "Microsoft.Maintenance/maintenanceConfigurations/maintenanceScope/InGuestPatch/write",
        "Microsoft.Maintenance/maintenanceConfigurations/maintenanceScope/InGuestPatch/delete"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Scheduled Patching Contributor",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Site Recovery-deltagare

Gör att du kan hantera Site Recovery-tjänsten förutom skapande av valv och rolltilldelning

Läs mer

Åtgärder beskrivning
Microsoft.Authorization/*/read Läsa roller och rolltilldelningar
Microsoft.Insights/alertRules/* Skapa och hantera en klassisk måttavisering
Microsoft.Network/virtualNetworks/read Hämta definitionen för virtuellt nätverk
Microsoft.RecoveryServices/locations/allocatedStamp/read GetAllocatedStamp är en intern åtgärd som används av tjänsten
Microsoft.RecoveryServices/locations/allocateStamp/action AllocateStamp är en intern åtgärd som används av tjänsten
Microsoft.RecoveryServices/Vaults/certificates/write Åtgärden Uppdatera resurscertifikat uppdaterar autentiseringscertifikatet för resurs/valv.
Microsoft.RecoveryServices/Vaults/extendedInformation/* Skapa och hantera utökad information om valv
Microsoft.RecoveryServices/Vaults/read Åtgärden Get Vault hämtar ett objekt som representerar Azure-resursen av typen "valv"
Microsoft.RecoveryServices/Vaults/refreshContainers/read
Microsoft.RecoveryServices/Vaults/registeredIdentiteter/* Skapa och hantera registrerade identiteter
Microsoft.RecoveryServices/vaults/replicationAlert Inställningar/* Skapa eller uppdatera aviseringsinställningar för replikering
Microsoft.RecoveryServices/vaults/replicationEvents/read Läs alla händelser
Microsoft.RecoveryServices/vaults/replicationFabrics/* Skapa och hantera replikeringsinfrastrukturer
Microsoft.RecoveryServices/vaults/replicationJobs/* Skapa och hantera replikeringsjobb
Microsoft.RecoveryServices/vaults/replicationPolicies/* Skapa och hantera replikeringsprinciper
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/* Skapa och hantera återställningsplaner
Microsoft.RecoveryServices/vaults/replicationVault Inställningar/*
Microsoft.RecoveryServices/Vaults/storageConfig/* Skapa och hantera lagringskonfiguration för Recovery Services-valv
Microsoft.RecoveryServices/Vaults/tokenInfo/read
Microsoft.RecoveryServices/Vaults/usages/read Returnerar användningsinformation för ett Recovery Services-valv.
Microsoft.RecoveryServices/Vaults/vaultTokens/read Åtgärden Valvtoken kan användas för att hämta valvtoken för backend-åtgärder på valvnivå.
Microsoft.RecoveryServices/Vaults/monitoringAlerts/* Läsa aviseringar för Recovery Services-valvet
Microsoft.RecoveryServices/Vaults/monitoringConfigurations/notificationConfiguration/read
Microsoft.ResourceHealth/availabilityStatuses/read Hämtar tillgänglighetsstatusar för alla resurser i det angivna omfånget
Microsoft.Resources/deployments/* Skapa och hantera en distribution
Microsoft.Resources/subscriptions/resourceGroups/read Hämtar eller listar resursgrupper.
Microsoft.Storage/storageAccounts/read Returnerar listan över lagringskonton eller hämtar egenskaperna för det angivna lagringskontot.
Microsoft.RecoveryServices/vaults/replicationOperationStatus/read Läs valvreplikeringsåtgärdsstatus
Microsoft.Support/* Skapa och uppdatera ett supportärende
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Lets you manage Site Recovery service except vault creation and role assignment",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/6670b86e-a3f7-4917-ac9b-5d6ab1be4567",
  "name": "6670b86e-a3f7-4917-ac9b-5d6ab1be4567",
  "permissions": [
    {
      "actions": [
        "Microsoft.Authorization/*/read",
        "Microsoft.Insights/alertRules/*",
        "Microsoft.Network/virtualNetworks/read",
        "Microsoft.RecoveryServices/locations/allocatedStamp/read",
        "Microsoft.RecoveryServices/locations/allocateStamp/action",
        "Microsoft.RecoveryServices/Vaults/certificates/write",
        "Microsoft.RecoveryServices/Vaults/extendedInformation/*",
        "Microsoft.RecoveryServices/Vaults/read",
        "Microsoft.RecoveryServices/Vaults/refreshContainers/read",
        "Microsoft.RecoveryServices/Vaults/registeredIdentities/*",
        "Microsoft.RecoveryServices/vaults/replicationAlertSettings/*",
        "Microsoft.RecoveryServices/vaults/replicationEvents/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/*",
        "Microsoft.RecoveryServices/vaults/replicationJobs/*",
        "Microsoft.RecoveryServices/vaults/replicationPolicies/*",
        "Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/*",
        "Microsoft.RecoveryServices/vaults/replicationVaultSettings/*",
        "Microsoft.RecoveryServices/Vaults/storageConfig/*",
        "Microsoft.RecoveryServices/Vaults/tokenInfo/read",
        "Microsoft.RecoveryServices/Vaults/usages/read",
        "Microsoft.RecoveryServices/Vaults/vaultTokens/read",
        "Microsoft.RecoveryServices/Vaults/monitoringAlerts/*",
        "Microsoft.RecoveryServices/Vaults/monitoringConfigurations/notificationConfiguration/read",
        "Microsoft.ResourceHealth/availabilityStatuses/read",
        "Microsoft.Resources/deployments/*",
        "Microsoft.Resources/subscriptions/resourceGroups/read",
        "Microsoft.Storage/storageAccounts/read",
        "Microsoft.RecoveryServices/vaults/replicationOperationStatus/read",
        "Microsoft.Support/*"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Site Recovery Contributor",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Site Recovery-operatör

Låter dig redundans och återställning efter fel men inte utföra andra Site Recovery-hanteringsåtgärder

Läs mer

Åtgärder beskrivning
Microsoft.Authorization/*/read Läsa roller och rolltilldelningar
Microsoft.Insights/alertRules/* Skapa och hantera en klassisk måttavisering
Microsoft.Network/virtualNetworks/read Hämta definitionen för virtuellt nätverk
Microsoft.RecoveryServices/locations/allocatedStamp/read GetAllocatedStamp är en intern åtgärd som används av tjänsten
Microsoft.RecoveryServices/locations/allocateStamp/action AllocateStamp är en intern åtgärd som används av tjänsten
Microsoft.RecoveryServices/Vaults/extendedInformation/read Åtgärden Hämta utökad information hämtar ett objekts utökade information som representerar Azure-resursen av typen ?vault?
Microsoft.RecoveryServices/Vaults/read Åtgärden Get Vault hämtar ett objekt som representerar Azure-resursen av typen "valv"
Microsoft.RecoveryServices/Vaults/refreshContainers/read
Microsoft.RecoveryServices/Vaults/registeredIdentities/operationResults/read Åtgärden Hämta åtgärdsresultat kan användas för att hämta åtgärdsstatus och resultat för den asynkront skickade åtgärden
Microsoft.RecoveryServices/Vaults/registeredIdentities/read Åtgärden Hämta containrar kan användas för att få containrarna registrerade för en resurs.
Microsoft.RecoveryServices/vaults/replicationAlert Inställningar/read Läs eventuella aviseringar Inställningar
Microsoft.RecoveryServices/vaults/replicationEvents/read Läs alla händelser
Microsoft.RecoveryServices/vaults/replicationFabrics/checkConsistency/action Kontrollerar infrastrukturresursens konsekvens
Microsoft.RecoveryServices/vaults/replicationFabrics/read Läs alla infrastrukturresurser
Microsoft.RecoveryServices/vaults/replicationFabrics/reassociateGateway/action Associera gatewayen igen
Microsoft.RecoveryServices/vaults/replicationFabrics/renewcertificate/action Förnya certifikat för infrastrukturresurser
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/read Läsa alla nätverk
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/replicationNetworkMappings/read Läsa eventuella nätverksmappningar
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/read Läs alla skyddscontainrar
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectableItems/read Läs alla skyddsbara objekt
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/applyRecoveryPoint/action Tillämpa återställningspunkt
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/failoverCommit/action Incheckning av redundans
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/plannedFailover/action Planerad redundans
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/read Läsa alla skyddade objekt
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/recoveryPoints/read Läs eventuella replikeringsåterställningspunkter
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/repairReplication/action Reparera replikering
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/reProtect/action Återaktivera skyddet av skyddat objekt
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/switchprotection/action Växla skyddscontainer
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/testFailover/action Testa redundans
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/testFailoverCleanup/action Testa redundansrensning
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/unplannedFailover/action Redundans
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/updateMobilityService/action Uppdatera mobilitetstjänsten
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionContainerMappings/read Läsa eventuella skyddscontainermappningar
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/read Läs alla Recovery Services-leverantörer
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/refreshProvider/action Uppdatera provider
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/read Läs eventuella lagringsklassificeringar
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/replicationStorageClassificationMappings/read Läsa eventuella lagringsklassificeringsmappningar
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationvCenters/read Läs eventuella vCenters
Microsoft.RecoveryServices/vaults/replicationJobs/* Skapa och hantera replikeringsjobb
Microsoft.RecoveryServices/vaults/replicationPolicies/read Läs alla principer
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/failoverCommit/action Återställningsplan för redundansberedskap
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/plannedFailover/action Planerad återställningsplan för redundans
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/read Läs eventuella återställningsplaner
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/reProtect/action Återaktivera skydd för återställningsplan
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/testFailover/action Testa återställningsplan för redundans
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/testFailoverCleanup/action Återställningsplan för redundanstestning
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/unplannedFailover/action Återställningsplan för redundans
Microsoft.RecoveryServices/vaults/replicationVault Inställningar/read Läs alla
Microsoft.RecoveryServices/Vaults/monitoringAlerts/* Läsa aviseringar för Recovery Services-valvet
Microsoft.RecoveryServices/Vaults/monitoringConfigurations/notificationConfiguration/read
Microsoft.RecoveryServices/Vaults/storageConfig/read
Microsoft.RecoveryServices/Vaults/tokenInfo/read
Microsoft.RecoveryServices/Vaults/usages/read Returnerar användningsinformation för ett Recovery Services-valv.
Microsoft.RecoveryServices/Vaults/vaultTokens/read Åtgärden Valvtoken kan användas för att hämta valvtoken för backend-åtgärder på valvnivå.
Microsoft.ResourceHealth/availabilityStatuses/read Hämtar tillgänglighetsstatusar för alla resurser i det angivna omfånget
Microsoft.Resources/deployments/* Skapa och hantera en distribution
Microsoft.Resources/subscriptions/resourceGroups/read Hämtar eller listar resursgrupper.
Microsoft.Storage/storageAccounts/read Returnerar listan över lagringskonton eller hämtar egenskaperna för det angivna lagringskontot.
Microsoft.Support/* Skapa och uppdatera ett supportärende
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Lets you failover and failback but not perform other Site Recovery management operations",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/494ae006-db33-4328-bf46-533a6560a3ca",
  "name": "494ae006-db33-4328-bf46-533a6560a3ca",
  "permissions": [
    {
      "actions": [
        "Microsoft.Authorization/*/read",
        "Microsoft.Insights/alertRules/*",
        "Microsoft.Network/virtualNetworks/read",
        "Microsoft.RecoveryServices/locations/allocatedStamp/read",
        "Microsoft.RecoveryServices/locations/allocateStamp/action",
        "Microsoft.RecoveryServices/Vaults/extendedInformation/read",
        "Microsoft.RecoveryServices/Vaults/read",
        "Microsoft.RecoveryServices/Vaults/refreshContainers/read",
        "Microsoft.RecoveryServices/Vaults/registeredIdentities/operationResults/read",
        "Microsoft.RecoveryServices/Vaults/registeredIdentities/read",
        "Microsoft.RecoveryServices/vaults/replicationAlertSettings/read",
        "Microsoft.RecoveryServices/vaults/replicationEvents/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/checkConsistency/action",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/reassociateGateway/action",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/renewcertificate/action",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/replicationNetworkMappings/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectableItems/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/applyRecoveryPoint/action",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/failoverCommit/action",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/plannedFailover/action",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/recoveryPoints/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/repairReplication/action",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/reProtect/action",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/switchprotection/action",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/testFailover/action",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/testFailoverCleanup/action",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/unplannedFailover/action",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/updateMobilityService/action",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionContainerMappings/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/refreshProvider/action",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/replicationStorageClassificationMappings/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationvCenters/read",
        "Microsoft.RecoveryServices/vaults/replicationJobs/*",
        "Microsoft.RecoveryServices/vaults/replicationPolicies/read",
        "Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/failoverCommit/action",
        "Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/plannedFailover/action",
        "Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/read",
        "Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/reProtect/action",
        "Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/testFailover/action",
        "Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/testFailoverCleanup/action",
        "Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/unplannedFailover/action",
        "Microsoft.RecoveryServices/vaults/replicationVaultSettings/read",
        "Microsoft.RecoveryServices/Vaults/monitoringAlerts/*",
        "Microsoft.RecoveryServices/Vaults/monitoringConfigurations/notificationConfiguration/read",
        "Microsoft.RecoveryServices/Vaults/storageConfig/read",
        "Microsoft.RecoveryServices/Vaults/tokenInfo/read",
        "Microsoft.RecoveryServices/Vaults/usages/read",
        "Microsoft.RecoveryServices/Vaults/vaultTokens/read",
        "Microsoft.ResourceHealth/availabilityStatuses/read",
        "Microsoft.Resources/deployments/*",
        "Microsoft.Resources/subscriptions/resourceGroups/read",
        "Microsoft.Storage/storageAccounts/read",
        "Microsoft.Support/*"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Site Recovery Operator",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Site Recovery-läsare

Gör att du kan visa Site Recovery-status men inte utföra andra hanteringsåtgärder

Läs mer

Åtgärder beskrivning
Microsoft.Authorization/*/read Läsa roller och rolltilldelningar
Microsoft.RecoveryServices/locations/allocatedStamp/read GetAllocatedStamp är en intern åtgärd som används av tjänsten
Microsoft.RecoveryServices/Vaults/extendedInformation/read Åtgärden Hämta utökad information hämtar ett objekts utökade information som representerar Azure-resursen av typen ?vault?
Microsoft.RecoveryServices/Vaults/monitoringAlerts/read Hämtar aviseringarna för Recovery Services-valvet.
Microsoft.RecoveryServices/Vaults/monitoringConfigurations/notificationConfiguration/read
Microsoft.RecoveryServices/Vaults/read Åtgärden Get Vault hämtar ett objekt som representerar Azure-resursen av typen "valv"
Microsoft.RecoveryServices/Vaults/refreshContainers/read
Microsoft.RecoveryServices/Vaults/registeredIdentities/operationResults/read Åtgärden Hämta åtgärdsresultat kan användas för att hämta åtgärdsstatus och resultat för den asynkront skickade åtgärden
Microsoft.RecoveryServices/Vaults/registeredIdentities/read Åtgärden Hämta containrar kan användas för att få containrarna registrerade för en resurs.
Microsoft.RecoveryServices/vaults/replicationAlert Inställningar/read Läs eventuella aviseringar Inställningar
Microsoft.RecoveryServices/vaults/replicationEvents/read Läs alla händelser
Microsoft.RecoveryServices/vaults/replicationFabrics/read Läs alla infrastrukturresurser
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/read Läsa alla nätverk
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/replicationNetworkMappings/read Läsa eventuella nätverksmappningar
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/read Läs alla skyddscontainrar
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectableItems/read Läs alla skyddsbara objekt
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/read Läsa alla skyddade objekt
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/recoveryPoints/read Läs eventuella replikeringsåterställningspunkter
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionContainerMappings/read Läsa eventuella skyddscontainermappningar
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/read Läs alla Recovery Services-leverantörer
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/read Läs eventuella lagringsklassificeringar
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/replicationStorageClassificationMappings/read Läsa eventuella lagringsklassificeringsmappningar
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationvCenters/read Läs eventuella vCenters
Microsoft.RecoveryServices/vaults/replicationJobs/read Läs alla jobb
Microsoft.RecoveryServices/vaults/replicationPolicies/read Läs alla principer
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/read Läs eventuella återställningsplaner
Microsoft.RecoveryServices/vaults/replicationVault Inställningar/read Läs alla
Microsoft.RecoveryServices/Vaults/storageConfig/read
Microsoft.RecoveryServices/Vaults/tokenInfo/read
Microsoft.RecoveryServices/Vaults/usages/read Returnerar användningsinformation för ett Recovery Services-valv.
Microsoft.RecoveryServices/Vaults/vaultTokens/read Åtgärden Valvtoken kan användas för att hämta valvtoken för backend-åtgärder på valvnivå.
Microsoft.Support/* Skapa och uppdatera ett supportärende
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Lets you view Site Recovery status but not perform other management operations",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/dbaa88c4-0c30-4179-9fb3-46319faa6149",
  "name": "dbaa88c4-0c30-4179-9fb3-46319faa6149",
  "permissions": [
    {
      "actions": [
        "Microsoft.Authorization/*/read",
        "Microsoft.RecoveryServices/locations/allocatedStamp/read",
        "Microsoft.RecoveryServices/Vaults/extendedInformation/read",
        "Microsoft.RecoveryServices/Vaults/monitoringAlerts/read",
        "Microsoft.RecoveryServices/Vaults/monitoringConfigurations/notificationConfiguration/read",
        "Microsoft.RecoveryServices/Vaults/read",
        "Microsoft.RecoveryServices/Vaults/refreshContainers/read",
        "Microsoft.RecoveryServices/Vaults/registeredIdentities/operationResults/read",
        "Microsoft.RecoveryServices/Vaults/registeredIdentities/read",
        "Microsoft.RecoveryServices/vaults/replicationAlertSettings/read",
        "Microsoft.RecoveryServices/vaults/replicationEvents/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/replicationNetworkMappings/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectableItems/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/recoveryPoints/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionContainerMappings/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/replicationStorageClassificationMappings/read",
        "Microsoft.RecoveryServices/vaults/replicationFabrics/replicationvCenters/read",
        "Microsoft.RecoveryServices/vaults/replicationJobs/read",
        "Microsoft.RecoveryServices/vaults/replicationPolicies/read",
        "Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/read",
        "Microsoft.RecoveryServices/vaults/replicationVaultSettings/read",
        "Microsoft.RecoveryServices/Vaults/storageConfig/read",
        "Microsoft.RecoveryServices/Vaults/tokenInfo/read",
        "Microsoft.RecoveryServices/Vaults/usages/read",
        "Microsoft.RecoveryServices/Vaults/vaultTokens/read",
        "Microsoft.Support/*"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Site Recovery Reader",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Deltagare i supportbegäran

Gör att du kan skapa och hantera supportförfrågningar

Läs mer

Åtgärder beskrivning
Microsoft.Authorization/*/read Läsa roller och rolltilldelningar
Microsoft.Resources/subscriptions/resourceGroups/read Hämtar eller listar resursgrupper.
Microsoft.Support/* Skapa och uppdatera ett supportärende
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Lets you create and manage Support requests",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/cfd33db0-3dd1-45e3-aa9d-cdbdf3b6f24e",
  "name": "cfd33db0-3dd1-45e3-aa9d-cdbdf3b6f24e",
  "permissions": [
    {
      "actions": [
        "Microsoft.Authorization/*/read",
        "Microsoft.Resources/subscriptions/resourceGroups/read",
        "Microsoft.Support/*"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Support Request Contributor",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Taggdeltagare

Gör att du kan hantera taggar på entiteter utan att ge åtkomst till själva entiteterna.

Läs mer

Åtgärder beskrivning
Microsoft.Authorization/*/read Läsa roller och rolltilldelningar
Microsoft.Resources/subscriptions/resourceGroups/read Hämtar eller listar resursgrupper.
Microsoft.Resources/subscriptions/resourceGroups/resources/read Hämtar resurserna för resursgruppen.
Microsoft.Resources/subscriptions/resources/read Hämtar resurser för en prenumeration.
Microsoft.Resources/deployments/* Skapa och hantera en distribution
Microsoft.Insights/alertRules/* Skapa och hantera en klassisk måttavisering
Microsoft.Support/* Skapa och uppdatera ett supportärende
Microsoft.Resources/tags/*
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Lets you manage tags on entities, without providing access to the entities themselves.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/4a9ae827-6dc8-4573-8ac7-8239d42aa03f",
  "name": "4a9ae827-6dc8-4573-8ac7-8239d42aa03f",
  "permissions": [
    {
      "actions": [
        "Microsoft.Authorization/*/read",
        "Microsoft.Resources/subscriptions/resourceGroups/read",
        "Microsoft.Resources/subscriptions/resourceGroups/resources/read",
        "Microsoft.Resources/subscriptions/resources/read",
        "Microsoft.Resources/deployments/*",
        "Microsoft.Insights/alertRules/*",
        "Microsoft.Support/*",
        "Microsoft.Resources/tags/*"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Tag Contributor",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Mallspecifikationsdeltagare

Tillåter fullständig åtkomst till mallspecifikationsåtgärder i det tilldelade omfånget.

Åtgärder beskrivning
Microsoft.Resources/templateSpecs/* Skapa och hantera mallspecifikationer och mallspecifikationsversioner
Microsoft.Authorization/*/read Läsa roller och rolltilldelningar
Microsoft.Resources/deployments/* Skapa och hantera en distribution
Microsoft.Resources/subscriptions/resourceGroups/read Hämtar eller listar resursgrupper.
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Allows full access to Template Spec operations at the assigned scope.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/1c9b6475-caf0-4164-b5a1-2142a7116f4b",
  "name": "1c9b6475-caf0-4164-b5a1-2142a7116f4b",
  "permissions": [
    {
      "actions": [
        "Microsoft.Resources/templateSpecs/*",
        "Microsoft.Authorization/*/read",
        "Microsoft.Resources/deployments/*",
        "Microsoft.Resources/subscriptions/resourceGroups/read"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Template Spec Contributor",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Mallspecifikationsläsare

Tillåter läsåtkomst till mallspecifikationer i det tilldelade omfånget.

Åtgärder beskrivning
Microsoft.Resources/templateSpecs/*/read Hämta eller lista mallspecifikationer och mallspecifikationsversioner
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Allows read access to Template Specs at the assigned scope.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/392ae280-861d-42bd-9ea5-08ee6d83b80e",
  "name": "392ae280-861d-42bd-9ea5-08ee6d83b80e",
  "permissions": [
    {
      "actions": [
        "Microsoft.Resources/templateSpecs/*/read"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Template Spec Reader",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Nästa steg