last sync: 2020-Dec-02 15:37:50 UTC

Azure RBAC Role definition

SQL Security Manager

NameSQL Security Manager
Microsoft docs
Id056cd41c-7e88-42e1-933e-88ba6a50c9c3
DescriptionLets you manage the security-related policies of SQL servers and databases, but not access to them.
CreatedOn2015-06-16 18:44:40 UTC
UpdatedOn2020-10-19 18:20:20 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2020-10-20 13:29:34 change: Actions Actions: 'remove Microsoft.Sql/servers/auditingPolicies/*; remove Microsoft.Sql/servers/databases/auditingPolicies/*; remove Microsoft.Sql/servers/databases/connectionPolicies/*'
Actions
Operation Description Used in other Roles
Microsoft.Authorization/*/readno description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, Backup Contributor, Backup Operator, Backup Reader, Billing Reader, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Collaborative Data Contributor, Cosmos DB Account Reader Role, Cosmos DB Operator, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DevTest Labs User, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid EventSubscription Contributor, EventGrid EventSubscription Reader, HDInsight Cluster Operator, Integration Service Environment Contributor, Integration Service Environment Developer, Intelligent Systems Account Contributor, Key Vault Administrator (preview), Key Vault Certificates Officer (preview), Key Vault Contributor, Key Vault Crypto Officer (preview), Key Vault Reader (preview), Key Vault Secrets Officer (preview), Kubernetes Cluster - Azure Arc Onboarding, Lab Creator, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Security Reader, Services Hub Operator, SignalR AccessKey Reader, SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader, SQL DB Contributor, SQL Managed Instance Contributor, SQL Server Contributor, Storage Account Backup Contributor Role, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Insights/alertRules/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, BizTalk Contributor, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Collaborative Data Contributor, Cosmos DB Operator, Data Factory Contributor, Data Lake Analytics Developer, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid EventSubscription Contributor, HDInsight Cluster Operator, Intelligent Systems Account Contributor, Key Vault Administrator (preview), Key Vault Certificates Officer (preview), Key Vault Contributor, Key Vault Crypto Officer (preview), Key Vault Reader (preview), Key Vault Secrets Officer (preview), Kubernetes Cluster - Azure Arc Onboarding, Log Analytics Contributor, Logic App Contributor, Managed Identity Contributor, Managed Identity Operator, Monitoring Contributor, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Server Contributor, Storage Account Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Network/virtualNetworks/subnets/joinViaServiceEndpoint/actionJoins resource such as storage account or SQL database to a subnet. Not alertable. Avere Contributor, Cosmos DB Operator, DocumentDB Account Contributor , Storage Account Contributor
Microsoft.ResourceHealth/availabilityStatuses/readGets the availability statuses for all resources in the specified scope API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Automation Operator, BizTalk Contributor, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Cognitive Services User, Cosmos DB Operator, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, DNS Zone Contributor, DocumentDB Account Contributor, Intelligent Systems Account Contributor, Network Contributor, New Relic APM Account Contributor, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Manager (Legacy), Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Server Contributor, Storage Account Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Resources/deployments/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Kubernetes Service Contributor Role, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, Backup Contributor, Backup Operator, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Collaborative Data Contributor, Cosmos DB Operator, Data Box Contributor, Data Factory Contributor, Data Lake Analytics Developer, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid EventSubscription Contributor, Intelligent Systems Account Contributor, Key Vault Administrator (preview), Key Vault Certificates Officer (preview), Key Vault Contributor, Key Vault Crypto Officer (preview), Key Vault Reader (preview), Key Vault Secrets Officer (preview), Log Analytics Contributor, Logic App Contributor, Managed Application Contributor Role, Managed Applications Reader, Managed Identity Contributor, Managed Identity Operator, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Services Hub Operator, SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Server Contributor, Storage Account Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups. API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Avere Operator, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, Backup Contributor, Backup Operator, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Cognitive Services User, Collaborative Data Contributor, Cosmos DB Account Reader Role, Cosmos DB Operator, Cost Management Contributor, Cost Management Reader, Data Box Contributor, Data Factory Contributor, Data Lake Analytics Developer, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DevTest Labs User, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid EventSubscription Contributor, EventGrid EventSubscription Reader, Experimentation Administrator, Experimentation Contributor, HDInsight Cluster Operator, Intelligent Systems Account Contributor, Key Vault Administrator (preview), Key Vault Certificates Officer (preview), Key Vault Contributor, Key Vault Crypto Officer (preview), Key Vault Reader (preview), Key Vault Secrets Officer (preview), Kubernetes Cluster - Azure Arc Onboarding, Lab Creator, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Monitoring Metrics Publisher, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Redis Cache Contributor, Reservation Purchaser, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Security Reader, Services Hub Operator, SignalR AccessKey Reader, SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Server Contributor, Storage Account Backup Contributor Role, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Sql/locations/administratorAzureAsyncOperation/readGets the Managed instance azure async administrator operations result. none
Microsoft.Sql/managedInstances/azureADOnlyAuthentications/*no description given none
Microsoft.Sql/managedInstances/databases/currentSensitivityLabels/*no description given none
Microsoft.Sql/managedInstances/databases/recommendedSensitivityLabels/*no description given none
Microsoft.Sql/managedInstances/databases/schemas/tables/columns/sensitivityLabels/*no description given none
Microsoft.Sql/managedInstances/databases/securityAlertPolicies/*no description given none
Microsoft.Sql/managedInstances/databases/sensitivityLabels/*no description given none
Microsoft.Sql/managedInstances/databases/transparentDataEncryption/*no description given none
Microsoft.Sql/managedInstances/databases/vulnerabilityAssessments/*no description given none
Microsoft.Sql/managedInstances/readReturn the list of managed instances or gets the properties for the specified managed instance. none
Microsoft.Sql/managedInstances/securityAlertPolicies/*no description given none
Microsoft.Sql/managedInstances/vulnerabilityAssessments/*no description given none
Microsoft.Sql/servers/auditingSettings/*no description given none
Microsoft.Sql/servers/azureADOnlyAuthentications/*no description given none
Microsoft.Sql/servers/databases/auditingSettings/*no description given none
Microsoft.Sql/servers/databases/auditRecords/readRetrieve the database blob audit records none
Microsoft.Sql/servers/databases/currentSensitivityLabels/*no description given none
Microsoft.Sql/servers/databases/dataMaskingPolicies/*no description given none
Microsoft.Sql/servers/databases/extendedAuditingSettings/readRetrieve details of the extended blob auditing policy configured on a given database none
Microsoft.Sql/servers/databases/readReturn the list of databases or gets the properties for the specified database. none
Microsoft.Sql/servers/databases/recommendedSensitivityLabels/*no description given none
Microsoft.Sql/servers/databases/schemas/readGet a database schema. none
Microsoft.Sql/servers/databases/schemas/tables/columns/readGet a database column. none
Microsoft.Sql/servers/databases/schemas/tables/columns/sensitivityLabels/*no description given none
Microsoft.Sql/servers/databases/schemas/tables/readGet a database table. none
Microsoft.Sql/servers/databases/securityAlertPolicies/*no description given none
Microsoft.Sql/servers/databases/securityMetrics/*no description given none
Microsoft.Sql/servers/databases/sensitivityLabels/*no description given none
Microsoft.Sql/servers/databases/transparentDataEncryption/*no description given none
Microsoft.Sql/servers/databases/vulnerabilityAssessments/*no description given none
Microsoft.Sql/servers/databases/vulnerabilityAssessmentScans/*no description given none
Microsoft.Sql/servers/databases/vulnerabilityAssessmentSettings/*no description given none
Microsoft.Sql/servers/extendedAuditingSettings/readRetrieve details of the extended server blob auditing policy configured on a given server none
Microsoft.Sql/servers/firewallRules/*no description given none
Microsoft.Sql/servers/readReturn the list of servers or gets the properties for the specified server. SQL DB Contributor
Microsoft.Sql/servers/securityAlertPolicies/*no description given none
Microsoft.Sql/servers/vulnerabilityAssessments/*no description given none
Microsoft.Support/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, Backup Contributor, Backup Operator, Billing Reader, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Cognitive Services User, Collaborative Data Contributor, Cosmos DB Account Reader Role, Cosmos DB Operator, Cost Management Contributor, Cost Management Reader, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid EventSubscription Contributor, HDInsight Cluster Operator, Integration Service Environment Contributor, Integration Service Environment Developer, Intelligent Systems Account Contributor, Key Vault Administrator (preview), Key Vault Certificates Officer (preview), Key Vault Contributor, Key Vault Crypto Officer (preview), Key Vault Reader (preview), Key Vault Secrets Officer (preview), Kubernetes Cluster - Azure Arc Onboarding, Lab Creator, Log Analytics Contributor, Log Analytics Reader, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Monitoring Contributor, Monitoring Metrics Publisher, Monitoring Reader, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Redis Cache Contributor, Resource Policy Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), SignalR AccessKey Reader, SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader, SQL DB Contributor, SQL Managed Instance Contributor, SQL Server Contributor, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, User Access Administrator, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in Policy
Policy DisplayName Policy Id Category State
Deploy Advanced Data Security on SQL servers 6134c3db-786f-471e-87bc-8f479dc890f6 SQL GA
Deploy Auditing on SQL servers f4c68484-132f-41f9-9b6d-3e4b1cb55036 SQL GA
Deploy Threat Detection on SQL servers 36d49e87-48c4-4f2e-beed-ba4ed02b71f5 SQL GA
Json
{
  "Name": "SQL Security Manager",
  "Id": "056cd41c-7e88-42e1-933e-88ba6a50c9c3",
  "IsCustom": false,
  "Description": "Lets you manage the security-related policies of SQL servers and databases, but not access to them.",
  "Actions": [
    "Microsoft.Authorization/*/read",
    "Microsoft.Insights/alertRules/*",
    "Microsoft.Network/virtualNetworks/subnets/joinViaServiceEndpoint/action",
    "Microsoft.ResourceHealth/availabilityStatuses/read",
    "Microsoft.Resources/deployments/*",
    "Microsoft.Resources/subscriptions/resourceGroups/read",
    "Microsoft.Sql/locations/administratorAzureAsyncOperation/read",
    "Microsoft.Sql/managedInstances/databases/currentSensitivityLabels/*",
    "Microsoft.Sql/managedInstances/databases/recommendedSensitivityLabels/*",
    "Microsoft.Sql/managedInstances/databases/schemas/tables/columns/sensitivityLabels/*",
    "Microsoft.Sql/managedInstances/databases/securityAlertPolicies/*",
    "Microsoft.Sql/managedInstances/databases/sensitivityLabels/*",
    "Microsoft.Sql/managedInstances/databases/vulnerabilityAssessments/*",
    "Microsoft.Sql/managedInstances/securityAlertPolicies/*",
    "Microsoft.Sql/managedInstances/databases/transparentDataEncryption/*",
    "Microsoft.Sql/managedInstances/vulnerabilityAssessments/*",
    "Microsoft.Sql/servers/auditingSettings/*",
    "Microsoft.Sql/servers/extendedAuditingSettings/read",
    "Microsoft.Sql/servers/databases/auditingSettings/*",
    "Microsoft.Sql/servers/databases/auditRecords/read",
    "Microsoft.Sql/servers/databases/currentSensitivityLabels/*",
    "Microsoft.Sql/servers/databases/dataMaskingPolicies/*",
    "Microsoft.Sql/servers/databases/extendedAuditingSettings/read",
    "Microsoft.Sql/servers/databases/read",
    "Microsoft.Sql/servers/databases/recommendedSensitivityLabels/*",
    "Microsoft.Sql/servers/databases/schemas/read",
    "Microsoft.Sql/servers/databases/schemas/tables/columns/read",
    "Microsoft.Sql/servers/databases/schemas/tables/columns/sensitivityLabels/*",
    "Microsoft.Sql/servers/databases/schemas/tables/read",
    "Microsoft.Sql/servers/databases/securityAlertPolicies/*",
    "Microsoft.Sql/servers/databases/securityMetrics/*",
    "Microsoft.Sql/servers/databases/sensitivityLabels/*",
    "Microsoft.Sql/servers/databases/transparentDataEncryption/*",
    "Microsoft.Sql/servers/databases/vulnerabilityAssessments/*",
    "Microsoft.Sql/servers/databases/vulnerabilityAssessmentScans/*",
    "Microsoft.Sql/servers/databases/vulnerabilityAssessmentSettings/*",
    "Microsoft.Sql/servers/firewallRules/*",
    "Microsoft.Sql/servers/read",
    "Microsoft.Sql/servers/securityAlertPolicies/*",
    "Microsoft.Sql/servers/vulnerabilityAssessments/*",
    "Microsoft.Support/*",
    "Microsoft.Sql/servers/azureADOnlyAuthentications/*",
    "Microsoft.Sql/managedInstances/read",
    "Microsoft.Sql/managedInstances/azureADOnlyAuthentications/*"
  ],
  "NotActions": [
    
  ],
  "DataActions": [
    
  ],
  "NotDataActions": [
    
  ],
  "AssignableScopes": [
    "/"
  ]
}