Inbyggda Azure-roller för Privileged

I den här artikeln visas de inbyggda Azure-rollerna i kategorin Privilegierad.

Deltagare

Ger fullständig åtkomst för att hantera alla resurser, men tillåter inte att du tilldelar roller i Azure RBAC, hanterar tilldelningar i Azure Blueprints eller delar bildgallerier.

Läs mer

Åtgärder beskrivning
* Skapa och hantera alla typer av resurser
NotActions
Microsoft.Authorization/*/Delete Ta bort roller, principtilldelningar, principdefinitioner och principuppsättningsdefinitioner
Microsoft.Authorization/*/Write Skapa roller, rolltilldelningar, principtilldelningar, principdefinitioner och principuppsättningsdefinitioner
Microsoft.Authorization/elevateAccess/Action Beviljar anroparen Användaråtkomst Administratörsåtkomst för klientomfånget
Microsoft.Blueprint/blueprintAssignments/write Skapa eller uppdatera skisstilldelningar
Microsoft.Blueprint/blueprintAssignments/delete Ta bort eventuella skisstilldelningar
Microsoft.Compute/galleries/share/action Delar ett galleri till olika omfång
Microsoft.Purview/consents/write Skapa eller uppdatera en medgivanderesurs.
Microsoft.Purview/consents/delete Ta bort medgivanderesursen.
Microsoft.Resources/deploymentStacks/manageDenySetting/action Hantera egenskapen denySettings för en distributionsstack.
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Grants full access to manage all resources, but does not allow you to assign roles in Azure RBAC, manage assignments in Azure Blueprints, or share image galleries.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/b24988ac-6180-42a0-ab88-20f7382dd24c",
  "name": "b24988ac-6180-42a0-ab88-20f7382dd24c",
  "permissions": [
    {
      "actions": [
        "*"
      ],
      "notActions": [
        "Microsoft.Authorization/*/Delete",
        "Microsoft.Authorization/*/Write",
        "Microsoft.Authorization/elevateAccess/Action",
        "Microsoft.Blueprint/blueprintAssignments/write",
        "Microsoft.Blueprint/blueprintAssignments/delete",
        "Microsoft.Compute/galleries/share/action",
        "Microsoft.Purview/consents/write",
        "Microsoft.Purview/consents/delete",
        "Microsoft.Resources/deploymentStacks/manageDenySetting/action"
      ],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Contributor",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Ägare

Ger fullständig åtkomst för att hantera alla resurser, inklusive möjligheten att tilldela roller i Azure RBAC.

Läs mer

Åtgärder beskrivning
* Skapa och hantera alla typer av resurser
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Grants full access to manage all resources, including the ability to assign roles in Azure RBAC.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/8e3af657-a8ff-443c-a75c-2fe8c4bcb635",
  "name": "8e3af657-a8ff-443c-a75c-2fe8c4bcb635",
  "permissions": [
    {
      "actions": [
        "*"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Owner",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Reservationsadministratör

Låter en läsa och hantera alla reservationer i en klientorganisation

Läs mer

Åtgärder beskrivning
Microsoft.Capacity/*/read
Microsoft.Capacity/*/action
Microsoft.Capacity/*/write
Microsoft.Authorization/roleAssignments/read Hämta information om en rolltilldelning.
Microsoft.Authorization/roleDefinitions/read Hämta information om en rolldefinition.
Microsoft.Authorization/roleAssignments/write Skapa en rolltilldelning i det angivna omfånget.
Microsoft.Authorization/roleAssignments/delete Ta bort en rolltilldelning i det angivna omfånget.
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/providers/Microsoft.Capacity"
  ],
  "description": "Lets one read and manage all the reservations in a tenant",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/a8889054-8d42-49c9-bc1c-52486c10e7cd",
  "name": "a8889054-8d42-49c9-bc1c-52486c10e7cd",
  "permissions": [
    {
      "actions": [
        "Microsoft.Capacity/*/read",
        "Microsoft.Capacity/*/action",
        "Microsoft.Capacity/*/write",
        "Microsoft.Authorization/roleAssignments/read",
        "Microsoft.Authorization/roleDefinitions/read",
        "Microsoft.Authorization/roleAssignments/write",
        "Microsoft.Authorization/roleAssignments/delete"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Reservations Administrator",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Administratör för rollbaserad åtkomstkontroll

Hantera åtkomst till Azure-resurser genom att tilldela roller med hjälp av Azure RBAC. Med den här rollen kan du inte hantera åtkomst på andra sätt, till exempel Azure Policy.

Åtgärder beskrivning
Microsoft.Authorization/roleAssignments/write Skapa en rolltilldelning i det angivna omfånget.
Microsoft.Authorization/roleAssignments/delete Ta bort en rolltilldelning i det angivna omfånget.
*/read Läsa resurser av alla typer, förutom hemligheter.
Microsoft.Support/* Skapa och uppdatera ett supportärende
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Manage access to Azure resources by assigning roles using Azure RBAC. This role does not allow you to manage access using other ways, such as Azure Policy.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/f58310d9-a9f6-439a-9e8d-f62e7b41a168",
  "name": "f58310d9-a9f6-439a-9e8d-f62e7b41a168",
  "permissions": [
    {
      "actions": [
        "Microsoft.Authorization/roleAssignments/write",
        "Microsoft.Authorization/roleAssignments/delete",
        "*/read",
        "Microsoft.Support/*"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "Role Based Access Control Administrator",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Administratör för användaråtkomst

Gör att du kan hantera användaråtkomst till Azure-resurser.

Läs mer

Åtgärder beskrivning
*/read Läsa resurser av alla typer, förutom hemligheter.
Microsoft.Authorization/* Hantera auktorisering
Microsoft.Support/* Skapa och uppdatera ett supportärende
NotActions
ingen
DataActions
ingen
NotDataActions
ingen
{
  "assignableScopes": [
    "/"
  ],
  "description": "Lets you manage user access to Azure resources.",
  "id": "/providers/Microsoft.Authorization/roleDefinitions/18d7d88d-d35e-4fb5-a5c3-7773c20a72d9",
  "name": "18d7d88d-d35e-4fb5-a5c3-7773c20a72d9",
  "permissions": [
    {
      "actions": [
        "*/read",
        "Microsoft.Authorization/*",
        "Microsoft.Support/*"
      ],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ],
  "roleName": "User Access Administrator",
  "roleType": "BuiltInRole",
  "type": "Microsoft.Authorization/roleDefinitions"
}

Nästa steg