last sync: 2023-Jun-07 17:44:45 UTC

Azure RBAC Role definition

SQL Security Manager

NameSQL Security Manager
Microsoft docs
Id056cd41c-7e88-42e1-933e-88ba6a50c9c3
DescriptionLets you manage the security-related policies of SQL servers and databases, but not access to them.
CreatedOn2015-06-16 18:44:40 UTC
UpdatedOn2023-03-03 16:46:08 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2023-03-03 18:43:27 change: Actions Actions: 'add Microsoft.Sql/managedInstances/serverConfigurationOptions/read; add Microsoft.Sql/managedInstances/serverConfigurationOptions/write; add Microsoft.Sql/locations/serverConfigurationOptionAzureAsyncOperation/read'
2022-12-12 17:45:20 change: Actions Actions: 'add Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/read; add Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/write; add Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/read; add Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/write; add Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/read; add Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/write; add Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/read; add Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/write; add Microsoft.Sql/servers/advancedThreatProtectionSettings/read; add Microsoft.Sql/servers/advancedThreatProtectionSettings/write; add Microsoft.Sql/servers/advancedThreatProtectionSettings/read; add Microsoft.Sql/servers/advancedThreatProtectionSettings/write; add Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/read; add Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/write; add Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/read; add Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/write'
2022-11-16 17:42:38 change: Actions Actions: 'add Microsoft.Sql/servers/databases/sqlvulnerabilityAssessments/*; add Microsoft.Sql/servers/sqlvulnerabilityAssessments/*; add Microsoft.Sql/servers/databases/ledgerDigestUploads/*; add Microsoft.Sql/locations/ledgerDigestUploadsAzureAsyncOperation/read; add Microsoft.Sql/locations/ledgerDigestUploadsOperationResults/read'
2022-04-28 17:39:09 change: Actions Actions: 'add Microsoft.Sql/servers/externalPolicyBasedAuthorizations/*'
2021-03-09 14:37:39 change: Actions Actions: 'add Microsoft.Sql/servers/devOpsAuditingSettings/*'
2021-02-15 15:24:20 change: Actions Actions: 'add Microsoft.Sql/managedInstances/administrators/read; add Microsoft.Sql/servers/administrators/read'
2020-12-10 15:11:36 change: Actions Actions: 'add Microsoft.Security/sqlVulnerabilityAssessments/*'
2020-10-20 13:29:34 change: Actions Actions: 'remove Microsoft.Sql/servers/auditingPolicies/*; remove Microsoft.Sql/servers/databases/auditingPolicies/*; remove Microsoft.Sql/servers/databases/connectionPolicies/*'
Actions
Operation Description Used in other Roles
Microsoft.Authorization/*/readno description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , API Management Service Workspace API Developer, API Management Service Workspace API Product Manager, API Management Workspace API Developer, API Management Workspace API Product Manager, API Management Workspace Contributor, API Management Workspace Reader, Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Contributor, Automation Job Operator, Automation Operator, Automation Runbook Operator, Autonomous Development Platform Data Contributor (Preview), Autonomous Development Platform Data Owner (Preview), Autonomous Development Platform Data Reader (Preview), Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Arc ScVmm Administrator role, Azure Arc ScVmm Private Cloud User, Azure Arc ScVmm Private Clouds Onboarding, Azure Arc ScVmm VM Contributor, Azure Arc VMware Administrator role , Azure Arc VMware Private Cloud User, Azure Arc VMware Private Clouds Onboarding, Azure Arc VMware VM Contributor, Azure Center for SAP solutions administrator, Azure Center for SAP solutions reader, Azure Kubernetes Fleet Manager RBAC Admin, Azure Kubernetes Fleet Manager RBAC Cluster Admin, Azure Kubernetes Fleet Manager RBAC Reader, Azure Kubernetes Fleet Manager RBAC Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Maps Contributor, Azure Sphere Contributor, Azure Sphere Publisher, Azure Sphere Reader, Azure VM Managed identities restore Contributor, Backup Contributor, Backup Operator, Backup Reader, Billing Reader, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Chamber Admin, Chamber User, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Code Signing Certificate Profile Signer, Cognitive Services Contributor, Collaborative Data Contributor, Collaborative Runtime Operator, ContainerApp Reader, Cosmos DB Account Reader Role, Cosmos DB Operator, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, Deployment Environments User, Desktop Virtualization Application Group Contributor, Desktop Virtualization Application Group Reader, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Host Pool Reader, Desktop Virtualization Power On Contributor, Desktop Virtualization Power On Off Contributor, Desktop Virtualization Reader, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Virtual Machine Contributor, Desktop Virtualization Workspace Contributor, Desktop Virtualization Workspace Reader, DevCenter Dev Box User, DevCenter Project Admin, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DevTest Labs User, Disk Backup Reader, Disk Pool Operator, Disk Restore Operator, Disk Snapshot Contributor, DNS Resolver Contributor, DNS Zone Contributor, DocumentDB Account Contributor, Domain Services Contributor, Domain Services Reader, Elastic SAN Owner, EventGrid Contributor, EventGrid Data Sender, EventGrid EventSubscription Contributor, EventGrid EventSubscription Reader, HDInsight Cluster Operator, Integration Service Environment Contributor, Integration Service Environment Developer, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Kubernetes Cluster - Azure Arc Onboarding, Kubernetes Extension Contributor, Lab Assistant, Lab Contributor, Lab Creator, Lab Operator, Lab Services Contributor, Lab Services Reader, Load Test Contributor, Load Test Owner, Load Test Reader, LocalNGFirewallAdministrator role, LocalRulestacksAdministrator role, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Management Group Contributor, Management Group Reader, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, Microsoft Sentinel Automation Contributor, Microsoft Sentinel Contributor, Microsoft Sentinel Reader, Microsoft Sentinel Responder, Network Contributor, New Relic APM Account Contributor, PlayFab Contributor, PlayFab Reader, Private DNS Zone Contributor, Quota Request Operator, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Security Reader, Services Hub Operator, SignalR AccessKey Reader, SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader, SQL DB Contributor, SQL Managed Instance Contributor, SQL Server Contributor, Storage Account Backup Contributor, Storage Account Contributor, Support Request Contributor, Tag Contributor, Template Spec Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor, Windows365SubscriptionReader
Microsoft.Insights/alertRules/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Center for SAP solutions administrator, Azure Center for SAP solutions reader, Azure Sphere Contributor, BizTalk Contributor, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Collaborative Data Contributor, Collaborative Runtime Operator, ContainerApp Reader, Cosmos DB Operator, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Power On Contributor, Desktop Virtualization Power On Off Contributor, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Virtual Machine Contributor, Desktop Virtualization Workspace Contributor, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, Disk Pool Operator, DNS Resolver Contributor, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid Contributor, EventGrid EventSubscription Contributor, HDInsight Cluster Operator, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Kubernetes Cluster - Azure Arc Onboarding, Kubernetes Extension Contributor, Lab Assistant, Lab Contributor, Lab Creator, Lab Operator, Lab Services Contributor, Load Test Contributor, Load Test Owner, Load Test Reader, LocalNGFirewallAdministrator role, LocalRulestacksAdministrator role, Log Analytics Contributor, Logic App Contributor, Managed Identity Contributor, Managed Identity Operator, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, Microsoft Sentinel Contributor, Microsoft Sentinel Reader, Microsoft Sentinel Responder, Monitoring Contributor, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Quota Request Operator, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Server Contributor, Storage Account Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Network/virtualNetworks/subnets/joinViaServiceEndpoint/actionJoins resource such as storage account or SQL database to a subnet. Not alertable. Avere Contributor, Cosmos DB Operator, DocumentDB Account Contributor , Storage Account Contributor
Microsoft.ResourceHealth/availabilityStatuses/readGets the availability statuses for all resources in the specified scope API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Automation Operator, Azure Arc ScVmm Administrator role, Azure Arc ScVmm Private Cloud User, Azure Arc ScVmm Private Clouds Onboarding, Azure Arc ScVmm VM Contributor, Azure Arc VMware Administrator role , Azure Arc VMware Private Cloud User, Azure Arc VMware Private Clouds Onboarding, Azure Arc VMware VM Contributor, Azure Center for SAP solutions administrator, Azure Center for SAP solutions reader, BizTalk Contributor, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Cognitive Services User, Cosmos DB Operator, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, DNS Zone Contributor, DocumentDB Account Contributor, Elastic SAN Owner, Elastic SAN Reader, Intelligent Systems Account Contributor, LocalNGFirewallAdministrator role, LocalRulestacksAdministrator role, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, Network Contributor, New Relic APM Account Contributor, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Manager (Legacy), Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Server Contributor, Storage Account Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Resources/deployments/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Contributor, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Center for SAP solutions administrator, Azure Center for SAP solutions reader, Azure Center for SAP solutions service role, Azure Connected Machine Resource Administrator, Azure Kubernetes Fleet Manager Contributor Role, Azure Kubernetes Service Contributor Role, Azure Kubernetes Service Policy Add-on Deployment, Azure Maps Contributor, Azure Sphere Contributor, Backup Contributor, Backup Operator, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Chamber Admin, Chamber User, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Code Signing Certificate Profile Signer, Cognitive Services Contributor, Collaborative Data Contributor, Collaborative Runtime Operator, ContainerApp Reader, Cosmos DB Operator, Data Box Contributor, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Power On Contributor, Desktop Virtualization Power On Off Contributor, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Virtual Machine Contributor, Desktop Virtualization Workspace Contributor, DevCenter Project Admin, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, Disk Pool Operator, DNS Resolver Contributor, DNS Zone Contributor, DocumentDB Account Contributor, Elastic SAN Owner, EventGrid Contributor, EventGrid EventSubscription Contributor, Guest Configuration Resource Contributor, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Kubernetes Extension Contributor, Lab Assistant, Lab Contributor, Lab Creator, Lab Operator, Lab Services Contributor, Lab Services Reader, Load Test Contributor, Load Test Owner, Load Test Reader, LocalNGFirewallAdministrator role, LocalRulestacksAdministrator role, Log Analytics Contributor, Logic App Contributor, Managed Application Contributor Role, Managed Applications Reader, Managed Identity Contributor, Managed Identity Operator, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, Microsoft Sentinel Contributor, Microsoft Sentinel Reader, Microsoft Sentinel Responder, Network Contributor, New Relic APM Account Contributor, PlayFab Contributor, Private DNS Zone Contributor, Quota Request Operator, Redis Cache Contributor, Resource Policy Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Services Hub Operator, SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Server Contributor, Storage Account Contributor, Tag Contributor, Template Spec Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups. API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , App Compliance Automation Administrator, Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Contributor, Automation Job Operator, Automation Operator, Automation Runbook Operator, Autonomous Development Platform Data Contributor (Preview), Autonomous Development Platform Data Owner (Preview), Autonomous Development Platform Data Reader (Preview), Avere Contributor, Avere Operator, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Arc ScVmm Administrator role, Azure Arc ScVmm Private Cloud User, Azure Arc ScVmm Private Clouds Onboarding, Azure Arc ScVmm VM Contributor, Azure Arc VMware Administrator role , Azure Arc VMware Private Cloud User, Azure Arc VMware Private Clouds Onboarding, Azure Arc VMware VM Contributor, Azure Center for SAP solutions administrator, Azure Center for SAP solutions reader, Azure Center for SAP solutions service role, Azure Front Door Domain Contributor, Azure Front Door Domain Reader, Azure Front Door Secret Contributor, Azure Front Door Secret Reader, Azure Kubernetes Fleet Manager RBAC Admin, Azure Kubernetes Fleet Manager RBAC Cluster Admin, Azure Kubernetes Fleet Manager RBAC Reader, Azure Kubernetes Fleet Manager RBAC Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Maps Contributor, Azure Sphere Contributor, Azure Sphere Publisher, Azure Sphere Reader, Azure Stack HCI registration role, Backup Contributor, Backup Operator, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Chamber Admin, Chamber User, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Code Signing Certificate Profile Signer, Cognitive Services Contributor, Cognitive Services User, Collaborative Data Contributor, Collaborative Runtime Operator, ContainerApp Reader, Cosmos DB Account Reader Role, Cosmos DB Operator, Cost Management Contributor, Cost Management Reader, Data Box Contributor, Data Factory Contributor, Data Lake Analytics Developer, Deployment Environments User, Desktop Virtualization Application Group Contributor, Desktop Virtualization Application Group Reader, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Host Pool Reader, Desktop Virtualization Power On Contributor, Desktop Virtualization Power On Off Contributor, Desktop Virtualization Reader, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Virtual Machine Contributor, Desktop Virtualization Workspace Contributor, Desktop Virtualization Workspace Reader, DevCenter Dev Box User, DevCenter Project Admin, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DevTest Labs User, Disk Pool Operator, Disk Restore Operator, Disk Snapshot Contributor, DNS Resolver Contributor, DNS Zone Contributor, DocumentDB Account Contributor, Domain Services Contributor, Domain Services Reader, Elastic SAN Owner, Elastic SAN Reader, EventGrid Contributor, EventGrid Data Sender, EventGrid EventSubscription Contributor, EventGrid EventSubscription Reader, Experimentation Administrator, Experimentation Contributor, HDInsight Cluster Operator, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Kubernetes Cluster - Azure Arc Onboarding, Kubernetes Extension Contributor, Lab Assistant, Lab Contributor, Lab Creator, Lab Operator, Lab Services Contributor, Lab Services Reader, Load Test Contributor, Load Test Owner, Load Test Reader, LocalNGFirewallAdministrator role, LocalRulestacksAdministrator role, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, Microsoft Sentinel Contributor, Microsoft Sentinel Reader, Microsoft Sentinel Responder, Monitoring Metrics Publisher, MySQL Backup And Export Operator, Network Contributor, New Relic APM Account Contributor, PlayFab Contributor, PlayFab Reader, Private DNS Zone Contributor, Quota Request Operator, Redis Cache Contributor, Reservation Purchaser, SaaS Hub Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Security Reader, Services Hub Operator, SignalR AccessKey Reader, SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Server Contributor, Storage Account Backup Contributor, Storage Account Contributor, Support Request Contributor, Tag Contributor, Template Spec Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor, Windows365NetworkInterfaceContributor
Microsoft.Security/sqlVulnerabilityAssessments/*no description given none
Microsoft.Sql/locations/administratorAzureAsyncOperation/readGets the Managed instance azure async administrator operations result. none
Microsoft.Sql/locations/ledgerDigestUploadsAzureAsyncOperation/readGets in-progress operations of ledger digest upload settings none
Microsoft.Sql/locations/ledgerDigestUploadsOperationResults/readGets in-progress operations of ledger digest upload settings none
Microsoft.Sql/locations/serverConfigurationOptionAzureAsyncOperation/readGets the status of Azure SQL Managed Instance Server Configuration Option Azure async operation. none
Microsoft.Sql/managedInstances/administrators/readGets a list of managed instance administrators. none
Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/readRetrieve a list of managed instance Advanced Threat Protection settings configured for a given instance none
Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/readRetrieve a list of managed instance Advanced Threat Protection settings configured for a given instance none
Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/writeChange the managed instance Advanced Threat Protection settings for a given managed instance none
Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/writeChange the managed instance Advanced Threat Protection settings for a given managed instance none
Microsoft.Sql/managedInstances/azureADOnlyAuthentications/*no description given none
Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/readRetrieve a list of the managed database Advanced Threat Protection settings configured for a given managed database none
Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/readRetrieve a list of the managed database Advanced Threat Protection settings configured for a given managed database none
Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/writeChange the database Advanced Threat Protection settings for a given managed database none
Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/writeChange the database Advanced Threat Protection settings for a given managed database none
Microsoft.Sql/managedInstances/databases/currentSensitivityLabels/*no description given none
Microsoft.Sql/managedInstances/databases/recommendedSensitivityLabels/*no description given none
Microsoft.Sql/managedInstances/databases/schemas/tables/columns/sensitivityLabels/*no description given none
Microsoft.Sql/managedInstances/databases/securityAlertPolicies/*no description given none
Microsoft.Sql/managedInstances/databases/sensitivityLabels/*no description given none
Microsoft.Sql/managedInstances/databases/transparentDataEncryption/*no description given none
Microsoft.Sql/managedInstances/databases/vulnerabilityAssessments/*no description given none
Microsoft.Sql/managedInstances/readReturn the list of managed instances or gets the properties for the specified managed instance. SqlMI Migration Role
Microsoft.Sql/managedInstances/securityAlertPolicies/*no description given none
Microsoft.Sql/managedInstances/serverConfigurationOptions/readGets properties for the specified Azure SQL Managed Instance Server Configuration Option. none
Microsoft.Sql/managedInstances/serverConfigurationOptions/writeUpdates Azure SQL Managed Instance's Server Configuration Option properties for the specified instance. none
Microsoft.Sql/managedInstances/vulnerabilityAssessments/*no description given none
Microsoft.Sql/servers/administrators/readGets a specific Azure Active Directory administrator object none
Microsoft.Sql/servers/advancedThreatProtectionSettings/readRetrieve a list of server Advanced Threat Protection settings configured for a given server none
Microsoft.Sql/servers/advancedThreatProtectionSettings/readRetrieve a list of server Advanced Threat Protection settings configured for a given server none
Microsoft.Sql/servers/advancedThreatProtectionSettings/writeChange the server Advanced Threat Protection settings for a given server none
Microsoft.Sql/servers/advancedThreatProtectionSettings/writeChange the server Advanced Threat Protection settings for a given server none
Microsoft.Sql/servers/auditingSettings/*no description given none
Microsoft.Sql/servers/azureADOnlyAuthentications/*no description given none
Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/readRetrieve a list of database Advanced Threat Protection settings configured for a given database none
Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/readRetrieve a list of database Advanced Threat Protection settings configured for a given database none
Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/writeChange the database Advanced Threat Protection settings for a given database none
Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/writeChange the database Advanced Threat Protection settings for a given database none
Microsoft.Sql/servers/databases/auditingSettings/*no description given none
Microsoft.Sql/servers/databases/auditRecords/readRetrieve the database blob audit records none
Microsoft.Sql/servers/databases/currentSensitivityLabels/*no description given none
Microsoft.Sql/servers/databases/dataMaskingPolicies/*no description given none
Microsoft.Sql/servers/databases/extendedAuditingSettings/readRetrieve details of the extended blob auditing policy configured on a given database none
Microsoft.Sql/servers/databases/ledgerDigestUploads/*no description given none
Microsoft.Sql/servers/databases/readReturn the list of databases or gets the properties for the specified database. SqlDb Migration Role
Microsoft.Sql/servers/databases/recommendedSensitivityLabels/*no description given none
Microsoft.Sql/servers/databases/schemas/readGet a database schema. none
Microsoft.Sql/servers/databases/schemas/tables/columns/readGet a database column. none
Microsoft.Sql/servers/databases/schemas/tables/columns/sensitivityLabels/*no description given none
Microsoft.Sql/servers/databases/schemas/tables/readGet a database table. none
Microsoft.Sql/servers/databases/securityAlertPolicies/*no description given none
Microsoft.Sql/servers/databases/securityMetrics/*no description given none
Microsoft.Sql/servers/databases/sensitivityLabels/*no description given none
Microsoft.Sql/servers/databases/sqlvulnerabilityAssessments/*no description given none
Microsoft.Sql/servers/databases/transparentDataEncryption/*no description given none
Microsoft.Sql/servers/databases/vulnerabilityAssessments/*no description given none
Microsoft.Sql/servers/databases/vulnerabilityAssessmentScans/*no description given none
Microsoft.Sql/servers/databases/vulnerabilityAssessmentSettings/*no description given none
Microsoft.Sql/servers/devOpsAuditingSettings/*no description given none
Microsoft.Sql/servers/extendedAuditingSettings/readRetrieve details of the extended server blob auditing policy configured on a given server none
Microsoft.Sql/servers/externalPolicyBasedAuthorizations/*no description given none
Microsoft.Sql/servers/firewallRules/*no description given none
Microsoft.Sql/servers/readReturn the list of servers or gets the properties for the specified server. SQL DB Contributor, SqlDb Migration Role
Microsoft.Sql/servers/securityAlertPolicies/*no description given none
Microsoft.Sql/servers/sqlvulnerabilityAssessments/*no description given none
Microsoft.Sql/servers/vulnerabilityAssessments/*no description given none
Microsoft.Support/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Contributor, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Backup Contributor, Backup Operator, Billing Reader, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Cognitive Services User, Collaborative Data Contributor, Collaborative Runtime Operator, Cosmos DB Account Reader Role, Cosmos DB Operator, Cost Management Contributor, Cost Management Reader, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Application Group Reader, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Host Pool Reader, Desktop Virtualization Reader, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Workspace Contributor, Desktop Virtualization Workspace Reader, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid Contributor, EventGrid EventSubscription Contributor, HDInsight Cluster Operator, Integration Service Environment Contributor, Integration Service Environment Developer, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Kubernetes Cluster - Azure Arc Onboarding, Lab Creator, LocalNGFirewallAdministrator role, LocalRulestacksAdministrator role, Log Analytics Contributor, Log Analytics Reader, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Microsoft Sentinel Contributor, Microsoft Sentinel Reader, Microsoft Sentinel Responder, Monitoring Contributor, Monitoring Metrics Publisher, Monitoring Reader, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Quota Request Operator, Redis Cache Contributor, Resource Policy Contributor, Role Based Access Control Administrator (Preview), Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), SignalR AccessKey Reader, SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader, SQL DB Contributor, SQL Managed Instance Contributor, SQL Server Contributor, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, User Access Administrator, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in Policy
Policy DisplayName Policy Id Category State
Configure Azure Defender to be enabled on SQL managed instances c5a62eb0-c65a-4220-8a4d-f70dd4ca95dd SQL GA
Configure Azure Defender to be enabled on SQL servers 36d49e87-48c4-4f2e-beed-ba4ed02b71f5 SQL GA
Configure Azure SQL database servers diagnostic settings to Log Analytics workspace 7ea8a143-05e3-4553-abfe-f56bef8b0b70 SQL GA
Configure Microsoft Defender for SQL to be enabled on Synapse workspaces 951c1558-50a5-4ca3-abb6-a93e3e2367a6 Security Center GA
Configure SQL servers to have auditing enabled f4c68484-132f-41f9-9b6d-3e4b1cb55036 SQL GA
Configure SQL servers to have auditing enabled to Log Analytics workspace 25da7dfb-0666-4a15-a8f5-402127efd8bb SQL GA
Configure Synapse workspaces to have auditing enabled ac7891a4-ac7a-4ba0-9ae9-c923e5a225ee Synapse GA
Deploy Advanced Data Security on SQL servers 6134c3db-786f-471e-87bc-8f479dc890f6 SQL GA
JSON