last sync: 2023-Sep-29 17:58:46 UTC

Azure RBAC Role definition

Domain Services Reader

NameDomain Services Reader
Microsoft docs
Id361898ef-9ed1-48c2-849c-a832951106bb
DescriptionCan view Azure AD Domain Services and related network configurations
CreatedOn2022-02-15 19:38:46 UTC
UpdatedOn2022-06-27 19:30:44 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2022-06-27 16:32:39 change: Actions Actions: 'add Microsoft.Insights/Logs/Read; add Microsoft.Insights/Metrics/read; add Microsoft.Insights/DiagnosticSettings/read; add Microsoft.Insights/DiagnosticSettingsCategories/Read'
2022-06-22 16:32:37 change: Actions Actions: 'remove Microsoft.AAD/domainServices/read; remove Microsoft.AAD/domainServices/oucontainer/read; remove Microsoft.AAD/domainServices/OutboundNetworkDependenciesEndpoints/read; remove Microsoft.AAD/domainServices/providers/Microsoft.Insights/diagnosticSettings/read; remove Microsoft.AAD/domainServices/providers/Microsoft.Insights/logDefinitions/read; add Microsoft.AAD/domainServices/*/read'
2022-02-23 18:03:00 add: Role 361898ef-9ed1-48c2-849c-a832951106bb
Actions
Operation Description Used in other Roles
Microsoft.AAD/domainServices/*/readno description given HDInsight Domain Services Contributor
Microsoft.Authorization/*/readno description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , API Management Service Workspace API Developer, API Management Service Workspace API Product Manager, API Management Workspace API Developer, API Management Workspace API Product Manager, API Management Workspace Contributor, API Management Workspace Reader, Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Contributor, Automation Job Operator, Automation Operator, Automation Runbook Operator, Autonomous Development Platform Data Contributor (Preview), Autonomous Development Platform Data Owner (Preview), Autonomous Development Platform Data Reader (Preview), Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Arc ScVmm Administrator role, Azure Arc ScVmm Private Cloud User, Azure Arc ScVmm Private Clouds Onboarding, Azure Arc ScVmm VM Contributor, Azure Arc VMware Administrator role , Azure Arc VMware Private Cloud User, Azure Arc VMware Private Clouds Onboarding, Azure Arc VMware VM Contributor, Azure Center for SAP solutions administrator, Azure Center for SAP solutions reader, Azure Kubernetes Fleet Manager RBAC Admin, Azure Kubernetes Fleet Manager RBAC Cluster Admin, Azure Kubernetes Fleet Manager RBAC Reader, Azure Kubernetes Fleet Manager RBAC Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Maps Contributor, Azure Sphere Contributor, Azure Sphere Publisher, Azure Sphere Reader, Azure VM Managed identities restore Contributor, Backup Contributor, Backup Operator, Backup Reader, Billing Reader, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Chamber Admin, Chamber User, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Code Signing Certificate Profile Signer, Cognitive Services Contributor, Collaborative Data Contributor, Collaborative Runtime Operator, Compute Diagnostics Role, ContainerApp Reader, Cosmos DB Account Reader Role, Cosmos DB Operator, Data Boundary Tenant Administrator, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, Deployment Environments User, Desktop Virtualization Application Group Contributor, Desktop Virtualization Application Group Reader, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Host Pool Reader, Desktop Virtualization Power On Contributor, Desktop Virtualization Power On Off Contributor, Desktop Virtualization Reader, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Virtual Machine Contributor, Desktop Virtualization Workspace Contributor, Desktop Virtualization Workspace Reader, DevCenter Dev Box User, DevCenter Project Admin, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DevTest Labs User, Disk Backup Reader, Disk Pool Operator, Disk Restore Operator, Disk Snapshot Contributor, DNS Resolver Contributor, DNS Zone Contributor, DocumentDB Account Contributor, Domain Services Contributor, Elastic SAN Owner, Elastic SAN Snapshot Exporter, Elastic SAN Volume Importer, EventGrid Contributor, EventGrid Data Sender, EventGrid EventSubscription Contributor, EventGrid EventSubscription Reader, Firmware Analysis Admin, HDInsight Cluster Operator, Integration Service Environment Contributor, Integration Service Environment Developer, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Data Access Administrator (preview), Key Vault Reader, Key Vault Secrets Officer, Kubernetes Cluster - Azure Arc Onboarding, Kubernetes Extension Contributor, Lab Assistant, Lab Contributor, Lab Creator, Lab Operator, Lab Services Contributor, Lab Services Reader, Load Test Contributor, Load Test Owner, Load Test Reader, LocalNGFirewallAdministrator role, LocalRulestacksAdministrator role, Logic App Contributor, Logic App Operator, Logic Apps Standard Contributor (Preview), Logic Apps Standard Developer (Preview), Logic Apps Standard Operator (Preview), Logic Apps Standard Reader (Preview), Managed Identity Contributor, Managed Identity Operator, Management Group Contributor, Management Group Reader, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, Microsoft Sentinel Automation Contributor, Microsoft Sentinel Contributor, Microsoft Sentinel Reader, Microsoft Sentinel Responder, Network Contributor, New Relic APM Account Contributor, PlayFab Contributor, PlayFab Reader, Private DNS Zone Contributor, Quota Request Operator, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Security Reader, Services Hub Operator, SignalR AccessKey Reader, SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Backup Contributor, Storage Account Contributor, Support Request Contributor, Tag Contributor, Template Spec Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor, Windows365SubscriptionReader
Microsoft.Insights/AlertRules/Incidents/ReadRead a classic metric alert incident Azure Arc ScVmm Administrator role, Azure Arc ScVmm Private Cloud User, Azure Arc ScVmm Private Clouds Onboarding , Azure Arc ScVmm VM Contributor, Azure Arc VMware Administrator role , Azure Arc VMware Private Cloud User, Azure Arc VMware Private Clouds Onboarding, Azure Arc VMware VM Contributor, Domain Services Contributor, HDInsight on AKS Cluster Admin, HDInsight on AKS Cluster Pool Admin
Microsoft.Insights/AlertRules/ReadRead a classic metric alert Azure Arc ScVmm Administrator role, Azure Arc ScVmm Private Cloud User, Azure Arc ScVmm Private Clouds Onboarding , Azure Arc ScVmm VM Contributor, Azure Arc VMware Administrator role , Azure Arc VMware Private Cloud User, Azure Arc VMware Private Clouds Onboarding, Azure Arc VMware VM Contributor, Cognitive Services User, Desktop Virtualization Application Group Reader, Desktop Virtualization Host Pool Reader, Desktop Virtualization Reader, Desktop Virtualization Workspace Reader, Domain Services Contributor, HDInsight on AKS Cluster Admin, HDInsight on AKS Cluster Pool Admin, Security Reader
Microsoft.Insights/DiagnosticSettings/readRead a resource diagnostic setting Azure Sphere Publisher, Azure Sphere Reader, Cognitive Services User
Microsoft.Insights/DiagnosticSettingsCategories/ReadRead diagnostic settings categories Azure Sphere Contributor, Domain Services Contributor
Microsoft.Insights/Logs/ReadReading data from all your logs Domain Services Contributor, HDInsight on AKS Cluster Admin, HDInsight on AKS Cluster Pool Admin
Microsoft.Insights/Metrics/readRead metrics Azure Center for SAP solutions administrator, Azure Center for SAP solutions reader, Cognitive Services Contributor , Cognitive Services User, Cosmos DB Account Reader Role, Domain Services Contributor, HDInsight on AKS Cluster Admin, HDInsight on AKS Cluster Pool Admin, LocalNGFirewallAdministrator role, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Server Contributor
Microsoft.Network/azureFirewalls/readGet Azure Firewall Domain Services Contributor
Microsoft.Network/ddosProtectionPlans/readGets a DDoS Protection Plan Domain Services Contributor
Microsoft.Network/loadBalancers/*/readno description given Domain Services Contributor
Microsoft.Network/loadBalancers/readGets a load balancer definition Azure Center for SAP solutions administrator, Azure Center for SAP solutions reader, Azure Center for SAP solutions service role , Domain Services Contributor, Virtual Machine Administrator Login, Virtual Machine Contributor, Virtual Machine User Login, Windows Admin Center Administrator Login
Microsoft.Network/natGateways/readGets a Nat Gateway Definition none
Microsoft.Network/networkInterfaces/readGets a network interface definition. Avere Operator, Azure Center for SAP solutions administrator, Azure Center for SAP solutions reader , Azure Center for SAP solutions service role, Desktop Virtualization Virtual Machine Contributor, DevTest Labs User, Domain Services Contributor, Virtual Machine Administrator Login, Virtual Machine User Login, Windows 365 Network Interface Contributor, Windows Admin Center Administrator Login
Microsoft.Network/networkSecurityGroups/defaultSecurityRules/readGets a default security rule definition Domain Services Contributor, Windows Admin Center Administrator Login
Microsoft.Network/networkSecurityGroups/readGets a network security group definition Desktop Virtualization Virtual Machine Contributor, Domain Services Contributor, LocalNGFirewallAdministrator role , Virtual Machine Contributor, Windows Admin Center Administrator Login
Microsoft.Network/networkSecurityGroups/securityRules/readGets a security rule definition Domain Services Contributor, Windows Admin Center Administrator Login
Microsoft.Network/routeTables/readGets a route table definition Domain Services Contributor
Microsoft.Network/routeTables/routes/readGets a route definition Domain Services Contributor
Microsoft.Network/virtualNetworks/providers/Microsoft.Insights/diagnosticSettings/readno description given Domain Services Contributor
Microsoft.Network/virtualNetworks/providers/Microsoft.Insights/metricDefinitions/readno description given Azure Center for SAP solutions administrator, Azure Center for SAP solutions reader, Domain Services Contributor
Microsoft.Network/virtualNetworks/readGet the virtual network definition Avere Contributor, Avere Operator, Azure Center for SAP solutions administrator , Azure Center for SAP solutions reader, Azure Center for SAP solutions service role, Backup Contributor, Backup Operator, Desktop Virtualization Virtual Machine Contributor, DNS Resolver Contributor, Domain Services Contributor, LocalNGFirewallAdministrator role, Private DNS Zone Contributor, Site Recovery Contributor, Site Recovery Operator, Virtual Machine Administrator Login, Virtual Machine Contributor, Virtual Machine User Login, Windows 365 Network User, Windows Admin Center Administrator Login
Microsoft.Network/virtualNetworks/subnets/readGets a virtual network subnet definition Avere Contributor, Avere Operator, Azure Center for SAP solutions administrator , Azure Center for SAP solutions reader, Azure Center for SAP solutions service role, Desktop Virtualization Virtual Machine Contributor, DNS Resolver Contributor, Domain Services Contributor, Windows 365 Network User
Microsoft.Network/virtualNetworks/virtualNetworkPeerings/readGets a virtual network peering definition Domain Services Contributor
Microsoft.Resources/deployments/operations/readGets or lists deployment operations. Azure Arc ScVmm Administrator role, Azure Arc ScVmm Private Cloud User, Azure Arc ScVmm Private Clouds Onboarding , Azure Arc ScVmm VM Contributor, Azure Arc VMware Administrator role , Azure Arc VMware Private Cloud User, Azure Arc VMware Private Clouds Onboarding, Azure Arc VMware VM Contributor, Cognitive Services Contributor, Cognitive Services User, DevTest Labs User, Domain Services Contributor, HDInsight Cluster Operator, HDInsight on AKS Cluster Admin, HDInsight on AKS Cluster Pool Admin, Logic App Operator, Logic Apps Standard Contributor (Preview), Logic Apps Standard Developer (Preview), Logic Apps Standard Operator (Preview), Logic Apps Standard Reader (Preview), Windows 365 Network Interface Contributor
Microsoft.Resources/deployments/operationstatuses/readGets or lists deployment operation statuses. Azure Arc ScVmm Administrator role, Azure Arc ScVmm Private Cloud User, Azure Arc ScVmm Private Clouds Onboarding , Azure Arc ScVmm VM Contributor, Azure Arc VMware Administrator role , Azure Arc VMware Private Cloud User, Azure Arc VMware Private Clouds Onboarding, Azure Arc VMware VM Contributor, Domain Services Contributor, Windows 365 Network Interface Contributor
Microsoft.Resources/deployments/readGets or lists deployments. Azure Arc ScVmm Administrator role, Azure Arc ScVmm Private Cloud User, Azure Arc ScVmm Private Clouds Onboarding , Azure Arc ScVmm VM Contributor, Azure Arc VMware Administrator role , Azure Arc VMware Private Cloud User, Azure Arc VMware Private Clouds Onboarding, Azure Arc VMware VM Contributor, Desktop Virtualization Application Group Reader, Desktop Virtualization Host Pool Reader, Desktop Virtualization Reader, Desktop Virtualization Workspace Reader, DevTest Labs User, Domain Services Contributor, HDInsight on AKS Cluster Admin, HDInsight on AKS Cluster Pool Admin, Windows 365 Network Interface Contributor
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups. API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , App Compliance Automation Administrator, Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Contributor, Automation Job Operator, Automation Operator, Automation Runbook Operator, Autonomous Development Platform Data Contributor (Preview), Autonomous Development Platform Data Owner (Preview), Autonomous Development Platform Data Reader (Preview), Avere Contributor, Avere Operator, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Arc ScVmm Administrator role, Azure Arc ScVmm Private Cloud User, Azure Arc ScVmm Private Clouds Onboarding, Azure Arc ScVmm VM Contributor, Azure Arc VMware Administrator role , Azure Arc VMware Private Cloud User, Azure Arc VMware Private Clouds Onboarding, Azure Arc VMware VM Contributor, Azure Center for SAP solutions administrator, Azure Center for SAP solutions reader, Azure Center for SAP solutions service role, Azure Front Door Domain Contributor, Azure Front Door Domain Reader, Azure Front Door Secret Contributor, Azure Front Door Secret Reader, Azure Kubernetes Fleet Manager RBAC Admin, Azure Kubernetes Fleet Manager RBAC Cluster Admin, Azure Kubernetes Fleet Manager RBAC Reader, Azure Kubernetes Fleet Manager RBAC Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Maps Contributor, Azure Sphere Contributor, Azure Sphere Publisher, Azure Sphere Reader, Azure Stack HCI registration role, Backup Contributor, Backup Operator, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Chamber Admin, Chamber User, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Code Signing Certificate Profile Signer, Cognitive Services Contributor, Cognitive Services User, Collaborative Data Contributor, Collaborative Runtime Operator, ContainerApp Reader, Cosmos DB Account Reader Role, Cosmos DB Operator, Cost Management Contributor, Cost Management Reader, Data Boundary Tenant Administrator, Data Box Contributor, Data Factory Contributor, Data Lake Analytics Developer, Deployment Environments User, Desktop Virtualization Application Group Contributor, Desktop Virtualization Application Group Reader, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Host Pool Reader, Desktop Virtualization Power On Contributor, Desktop Virtualization Power On Off Contributor, Desktop Virtualization Reader, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Virtual Machine Contributor, Desktop Virtualization Workspace Contributor, Desktop Virtualization Workspace Reader, DevCenter Dev Box User, DevCenter Project Admin, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DevTest Labs User, Disk Pool Operator, Disk Restore Operator, Disk Snapshot Contributor, DNS Resolver Contributor, DNS Zone Contributor, DocumentDB Account Contributor, Domain Services Contributor, Elastic SAN Owner, Elastic SAN Reader, Elastic SAN Snapshot Exporter, Elastic SAN Volume Importer, EventGrid Contributor, EventGrid Data Sender, EventGrid EventSubscription Contributor, EventGrid EventSubscription Reader, Experimentation Administrator, Experimentation Contributor, Firmware Analysis Admin, HDInsight Cluster Operator, HDInsight on AKS Cluster Admin, HDInsight on AKS Cluster Pool Admin, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Data Access Administrator (preview), Key Vault Reader, Key Vault Secrets Officer, Kubernetes Cluster - Azure Arc Onboarding, Kubernetes Extension Contributor, Lab Assistant, Lab Contributor, Lab Creator, Lab Operator, Lab Services Contributor, Lab Services Reader, Load Test Contributor, Load Test Owner, Load Test Reader, LocalNGFirewallAdministrator role, LocalRulestacksAdministrator role, Logic App Contributor, Logic App Operator, Logic Apps Standard Contributor (Preview), Logic Apps Standard Developer (Preview), Logic Apps Standard Operator (Preview), Logic Apps Standard Reader (Preview), Managed Identity Contributor, Managed Identity Operator, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, Microsoft Sentinel Contributor, Microsoft Sentinel Reader, Microsoft Sentinel Responder, Monitoring Metrics Publisher, MySQL Backup And Export Operator, Network Contributor, New Relic APM Account Contributor, PlayFab Contributor, PlayFab Reader, PostgreSQL Flexible Server Long Term Retention Backup Role, Private DNS Zone Contributor, Procurement Contributor, Quota Request Operator, Redis Cache Contributor, Reservation Purchaser, SaaS Hub Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Security Reader, Services Hub Operator, SignalR AccessKey Reader, SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Backup Contributor, Storage Account Contributor, Support Request Contributor, Tag Contributor, Template Spec Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor, Windows 365 Network Interface Contributor
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in Policy none
JSON
api-version=2022-05-01-preview