last sync: 2022-Sep-27 16:35:31 UTC

Azure RBAC Role definition

Azure Kubernetes Service Policy Add-on Deployment

NameAzure Kubernetes Service Policy Add-on Deployment
Id18ed5180-3e48-46fd-8541-4ea054d57064
DescriptionDeploy the Azure Policy add-on on Azure Kubernetes Service clusters
CreatedOn2022-02-07 20:51:48 UTC
UpdatedOn2022-03-15 19:19:25 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2022-03-16 17:58:57 change: Actions Actions: 'add Microsoft.Compute/diskEncryptionSets/read; add Microsoft.Compute/proximityPlacementGroups/write'
2022-02-10 17:19:06 change: Actions Actions: 'add Microsoft.Network/virtualNetworks/subnets/join/action; add Microsoft.Network/publicIPPrefixes/join/action; add Microsoft.Network/publicIPAddresses/join/action'
2022-02-08 18:24:32 add: Role 18ed5180-3e48-46fd-8541-4ea054d57064
Actions
Operation Description Used in other Roles
Microsoft.Compute/diskEncryptionSets/readGet the properties of a disk encryption set none
Microsoft.Compute/proximityPlacementGroups/writeCreates a new Proximity Placement Group or updates an existing one none
Microsoft.Network/publicIPAddresses/join/actionJoins a public ip address. Not Alertable. DevTest Labs User, Virtual Machine Contributor
Microsoft.Network/publicIPPrefixes/join/actionJoins a PublicIPPrefix. Not alertable. none
Microsoft.Network/virtualNetworks/subnets/join/actionJoins a virtual network. Not Alertable. Avere Contributor, Avere Operator, Desktop Virtualization Virtual Machine Contributor , DevTest Labs User, DNS Resolver Contributor, Domain Services Contributor, Virtual Machine Contributor
Microsoft.Resources/deployments/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Contributor, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Connected Machine Resource Administrator, Azure Kubernetes Fleet Manager Contributor Role, Azure Kubernetes Service Contributor Role, Azure Maps Contributor, Backup Contributor, Backup Operator, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Chamber Admin, Chamber User, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, CodeSigning Certificate Profile Signer, Cognitive Services Contributor, Collaborative Data Contributor, Collaborative Runtime Operator, Cosmos DB Operator, Data Box Contributor, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Power On Contributor, Desktop Virtualization Power On Off Contributor, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Virtual Machine Contributor, Desktop Virtualization Workspace Contributor, DevCenter Project Admin, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, Disk Pool Operator, DNS Resolver Contributor, DNS Zone Contributor, DocumentDB Account Contributor, Elastic SAN Owner, EventGrid Contributor, EventGrid EventSubscription Contributor, Guest Configuration Resource Contributor, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Kubernetes Extension Contributor, Lab Assistant, Lab Contributor, Lab Creator, Lab Operator, Lab Services Contributor, Lab Services Reader, Load Test Contributor, Load Test Owner, Load Test Reader, Log Analytics Contributor, Logic App Contributor, Managed Application Contributor Role, Managed Applications Reader, Managed Identity Contributor, Managed Identity Operator, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, Microsoft Sentinel Contributor, Microsoft Sentinel Reader, Microsoft Sentinel Responder, Network Contributor, New Relic APM Account Contributor, PlayFab Contributor, Private DNS Zone Contributor, Quota Request Operator, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Services Hub Operator, SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Tag Contributor, Template Spec Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in Policy
Policy DisplayName Policy Id Category State
Configure AAD integrated Azure Kubernetes Service Clusters with required Admin Group Access 36a27de4-199b-40fb-b336-945a8475d6c5 Kubernetes GA
Deploy Azure Policy Add-on to Azure Kubernetes Service clusters a8eff44f-8c92-45c3-a3fb-9880802d67a7 Kubernetes GA
Disable Command Invoke on Azure Kubernetes Service clusters 1b708b0a-3380-40e9-8b79-821f9fa224cc Kubernetes GA
JSON