last sync: 2023-Sep-26 18:00:52 UTC

Azure RBAC Role definition

Virtual Machine Contributor

NameVirtual Machine Contributor
Microsoft docs
Id9980e02c-c2be-4d73-94e8-173b1dc7cf3c
DescriptionLets you manage virtual machines, but not access to them, and not the virtual network or storage account they're connected to.
CreatedOn2015-06-02 00:18:27 UTC
UpdatedOn2021-11-11 20:13:58 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2021-10-01 15:34:12 change: Actions Actions: 'add Microsoft.Compute/cloudServices/*'
2021-08-19 16:32:19 change: Actions Actions: 'add Microsoft.SerialConsole/serialPorts/connect/action'
Actions
Operation Description Used in other Roles
Microsoft.Authorization/*/readno description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , API Management Service Workspace API Developer, API Management Service Workspace API Product Manager, API Management Workspace API Developer, API Management Workspace API Product Manager, API Management Workspace Contributor, API Management Workspace Reader, Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Contributor, Automation Job Operator, Automation Operator, Automation Runbook Operator, Autonomous Development Platform Data Contributor (Preview), Autonomous Development Platform Data Owner (Preview), Autonomous Development Platform Data Reader (Preview), Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Arc ScVmm Administrator role, Azure Arc ScVmm Private Cloud User, Azure Arc ScVmm Private Clouds Onboarding, Azure Arc ScVmm VM Contributor, Azure Arc VMware Administrator role , Azure Arc VMware Private Cloud User, Azure Arc VMware Private Clouds Onboarding, Azure Arc VMware VM Contributor, Azure Center for SAP solutions administrator, Azure Center for SAP solutions reader, Azure Kubernetes Fleet Manager RBAC Admin, Azure Kubernetes Fleet Manager RBAC Cluster Admin, Azure Kubernetes Fleet Manager RBAC Reader, Azure Kubernetes Fleet Manager RBAC Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Maps Contributor, Azure Sphere Contributor, Azure Sphere Publisher, Azure Sphere Reader, Azure VM Managed identities restore Contributor, Backup Contributor, Backup Operator, Backup Reader, Billing Reader, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Chamber Admin, Chamber User, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Code Signing Certificate Profile Signer, Cognitive Services Contributor, Collaborative Data Contributor, Collaborative Runtime Operator, Compute Diagnostics Role, ContainerApp Reader, Cosmos DB Account Reader Role, Cosmos DB Operator, Data Boundary Tenant Administrator, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, Deployment Environments User, Desktop Virtualization Application Group Contributor, Desktop Virtualization Application Group Reader, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Host Pool Reader, Desktop Virtualization Power On Contributor, Desktop Virtualization Power On Off Contributor, Desktop Virtualization Reader, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Virtual Machine Contributor, Desktop Virtualization Workspace Contributor, Desktop Virtualization Workspace Reader, DevCenter Dev Box User, DevCenter Project Admin, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DevTest Labs User, Disk Backup Reader, Disk Pool Operator, Disk Restore Operator, Disk Snapshot Contributor, DNS Resolver Contributor, DNS Zone Contributor, DocumentDB Account Contributor, Domain Services Contributor, Domain Services Reader, Elastic SAN Owner, Elastic SAN Snapshot Exporter, Elastic SAN Volume Importer, EventGrid Contributor, EventGrid Data Sender, EventGrid EventSubscription Contributor, EventGrid EventSubscription Reader, Firmware Analysis Admin, HDInsight Cluster Operator, Integration Service Environment Contributor, Integration Service Environment Developer, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Data Access Administrator (preview), Key Vault Reader, Key Vault Secrets Officer, Kubernetes Cluster - Azure Arc Onboarding, Kubernetes Extension Contributor, Lab Assistant, Lab Contributor, Lab Creator, Lab Operator, Lab Services Contributor, Lab Services Reader, Load Test Contributor, Load Test Owner, Load Test Reader, LocalNGFirewallAdministrator role, LocalRulestacksAdministrator role, Logic App Contributor, Logic App Operator, Logic Apps Standard Contributor (Preview), Logic Apps Standard Developer (Preview), Logic Apps Standard Operator (Preview), Logic Apps Standard Reader (Preview), Managed Identity Contributor, Managed Identity Operator, Management Group Contributor, Management Group Reader, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, Microsoft Sentinel Automation Contributor, Microsoft Sentinel Contributor, Microsoft Sentinel Reader, Microsoft Sentinel Responder, Network Contributor, New Relic APM Account Contributor, PlayFab Contributor, PlayFab Reader, Private DNS Zone Contributor, Quota Request Operator, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Security Reader, Services Hub Operator, SignalR AccessKey Reader, SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Backup Contributor, Storage Account Contributor, Support Request Contributor, Tag Contributor, Template Spec Contributor, Traffic Manager Contributor, Web Plan Contributor, Website Contributor, Windows365SubscriptionReader
Microsoft.Compute/availabilitySets/*no description given Avere Contributor
Microsoft.Compute/cloudServices/*no description given none
Microsoft.Compute/disks/deleteDeletes the Disk Desktop Virtualization Virtual Machine Contributor, Elastic SAN Snapshot Exporter
Microsoft.Compute/disks/readGet the properties of a Disk Azure Center for SAP solutions administrator, Azure Center for SAP solutions reader, Azure Center for SAP solutions service role , Desktop Virtualization Virtual Machine Contributor, Disk Backup Reader, Disk Pool Operator, Disk Restore Operator, Elastic SAN Snapshot Exporter, Elastic SAN Volume Importer, VM Scanner Operator
Microsoft.Compute/disks/writeCreates a new Disk or updates an existing one Azure Center for SAP solutions service role, Desktop Virtualization Virtual Machine Contributor, Disk Pool Operator , Disk Restore Operator, Elastic SAN Snapshot Exporter
Microsoft.Compute/locations/*no description given Elastic SAN Snapshot Exporter, Elastic SAN Volume Importer
Microsoft.Compute/virtualMachines/*no description given Avere Contributor
Microsoft.Compute/virtualMachineScaleSets/*no description given none
Microsoft.DevTestLab/schedules/*no description given none
Microsoft.Insights/alertRules/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Center for SAP solutions administrator, Azure Center for SAP solutions reader, Azure Sphere Contributor, BizTalk Contributor, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Collaborative Data Contributor, Collaborative Runtime Operator, ContainerApp Reader, Cosmos DB Operator, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Power On Contributor, Desktop Virtualization Power On Off Contributor, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Virtual Machine Contributor, Desktop Virtualization Workspace Contributor, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, Disk Pool Operator, DNS Resolver Contributor, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid Contributor, EventGrid EventSubscription Contributor, HDInsight Cluster Operator, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Kubernetes Cluster - Azure Arc Onboarding, Kubernetes Extension Contributor, Lab Assistant, Lab Contributor, Lab Creator, Lab Operator, Lab Services Contributor, Load Test Contributor, Load Test Owner, Load Test Reader, LocalNGFirewallAdministrator role, LocalRulestacksAdministrator role, Log Analytics Contributor, Logic App Contributor, Logic Apps Standard Contributor (Preview), Logic Apps Standard Developer (Preview), Logic Apps Standard Operator (Preview), Logic Apps Standard Reader (Preview), Managed Identity Contributor, Managed Identity Operator, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, Microsoft Sentinel Contributor, Microsoft Sentinel Reader, Microsoft Sentinel Responder, Monitoring Contributor, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Quota Request Operator, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Tag Contributor, Traffic Manager Contributor, Web Plan Contributor, Website Contributor
Microsoft.Network/applicationGateways/backendAddressPools/join/actionJoins an application gateway backend address pool. Not Alertable. none
Microsoft.Network/loadBalancers/backendAddressPools/join/actionJoins a load balancer backend address pool. Not Alertable. Azure Center for SAP solutions service role, DevTest Labs User, Domain Services Contributor
Microsoft.Network/loadBalancers/inboundNatPools/join/actionJoins a load balancer inbound NAT pool. Not alertable. none
Microsoft.Network/loadBalancers/inboundNatRules/join/actionJoins a load balancer inbound nat rule. Not Alertable. DevTest Labs User, Domain Services Contributor
Microsoft.Network/loadBalancers/probes/join/actionAllows using probes of a load balancer. For example, with this permission healthProbe property of VM scale set can reference the probe. Not alertable. none
Microsoft.Network/loadBalancers/readGets a load balancer definition Azure Center for SAP solutions administrator, Azure Center for SAP solutions reader, Azure Center for SAP solutions service role , Domain Services Contributor, Domain Services Reader, Virtual Machine Administrator Login, Virtual Machine User Login, Windows Admin Center Administrator Login
Microsoft.Network/locations/*no description given none
Microsoft.Network/networkInterfaces/*no description given Avere Contributor
Microsoft.Network/networkSecurityGroups/join/actionJoins a network security group. Not Alertable. Avere Contributor, Avere Operator, Azure Center for SAP solutions administrator , DNS Resolver Contributor, Domain Services Contributor, LocalNGFirewallAdministrator role
Microsoft.Network/networkSecurityGroups/readGets a network security group definition Desktop Virtualization Virtual Machine Contributor, Domain Services Contributor, Domain Services Reader , LocalNGFirewallAdministrator role, Windows Admin Center Administrator Login
Microsoft.Network/publicIPAddresses/join/actionJoins a public ip address. Not Alertable. Azure Kubernetes Service Policy Add-on Deployment, DevTest Labs User, LocalNGFirewallAdministrator role
Microsoft.Network/publicIPAddresses/readGets a public ip address definition. DevTest Labs User, LocalNGFirewallAdministrator role, Virtual Machine Administrator Login , Virtual Machine User Login, Windows Admin Center Administrator Login
Microsoft.Network/virtualNetworks/readGet the virtual network definition Avere Contributor, Avere Operator, Azure Center for SAP solutions administrator , Azure Center for SAP solutions reader, Azure Center for SAP solutions service role, Backup Contributor, Backup Operator, Desktop Virtualization Virtual Machine Contributor, DNS Resolver Contributor, Domain Services Contributor, Domain Services Reader, LocalNGFirewallAdministrator role, Private DNS Zone Contributor, Site Recovery Contributor, Site Recovery Operator, Virtual Machine Administrator Login, Virtual Machine User Login, Windows 365 Network User, Windows Admin Center Administrator Login
Microsoft.Network/virtualNetworks/subnets/join/actionJoins a virtual network. Not Alertable. Avere Contributor, Avere Operator, Azure Center for SAP solutions service role , Azure Kubernetes Service Policy Add-on Deployment, Desktop Virtualization Virtual Machine Contributor, DevTest Labs User, DNS Resolver Contributor, Domain Services Contributor, LocalNGFirewallAdministrator role, Windows 365 Network User
Microsoft.RecoveryServices/locations/*no description given Backup Contributor
Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/writeCreate a backup Protection Intent Backup Operator
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/*/readno description given none
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/readReturns object details of the Protected Item Backup Operator, Backup Reader
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/writeCreate a backup Protected Item Backup Operator
Microsoft.RecoveryServices/Vaults/backupPolicies/readReturns all Protection Policies Backup Operator, Backup Reader
Microsoft.RecoveryServices/Vaults/backupPolicies/writeCreates Protection Policy none
Microsoft.RecoveryServices/Vaults/readThe Get Vault operation gets an object representing the Azure resource of type 'vault' Backup Contributor, Backup Operator, Backup Reader , Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader
Microsoft.RecoveryServices/Vaults/usages/readRead any Vault Usages Backup Operator, Backup Reader, Site Recovery Contributor , Site Recovery Operator, Site Recovery Reader
Microsoft.RecoveryServices/Vaults/writeCreate Vault operation creates an Azure resource of type 'vault' Backup Contributor
Microsoft.ResourceHealth/availabilityStatuses/readGets the availability statuses for all resources in the specified scope API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Automation Operator, Azure Arc ScVmm Administrator role, Azure Arc ScVmm Private Cloud User, Azure Arc ScVmm Private Clouds Onboarding, Azure Arc ScVmm VM Contributor, Azure Arc VMware Administrator role , Azure Arc VMware Private Cloud User, Azure Arc VMware Private Clouds Onboarding, Azure Arc VMware VM Contributor, Azure Center for SAP solutions administrator, Azure Center for SAP solutions reader, BizTalk Contributor, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Cognitive Services User, Cosmos DB Operator, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, DNS Zone Contributor, DocumentDB Account Contributor, Elastic SAN Owner, Elastic SAN Reader, HDInsight on AKS Cluster Admin, HDInsight on AKS Cluster Pool Admin, Intelligent Systems Account Contributor, LocalNGFirewallAdministrator role, LocalRulestacksAdministrator role, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, Network Contributor, New Relic APM Account Contributor, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Manager (Legacy), Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Traffic Manager Contributor, Web Plan Contributor, Website Contributor
Microsoft.Resources/deployments/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Contributor, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Center for SAP solutions administrator, Azure Center for SAP solutions reader, Azure Center for SAP solutions service role, Azure Connected Machine Resource Administrator, Azure Kubernetes Fleet Manager Contributor Role, Azure Kubernetes Service Contributor Role, Azure Kubernetes Service Policy Add-on Deployment, Azure Maps Contributor, Azure Sphere Contributor, Backup Contributor, Backup Operator, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Chamber Admin, Chamber User, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Code Signing Certificate Profile Signer, Cognitive Services Contributor, Collaborative Data Contributor, Collaborative Runtime Operator, ContainerApp Reader, Cosmos DB Operator, Data Boundary Tenant Administrator, Data Box Contributor, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Power On Contributor, Desktop Virtualization Power On Off Contributor, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Virtual Machine Contributor, Desktop Virtualization Workspace Contributor, DevCenter Project Admin, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, Disk Pool Operator, DNS Resolver Contributor, DNS Zone Contributor, DocumentDB Account Contributor, Elastic SAN Owner, EventGrid Contributor, EventGrid EventSubscription Contributor, Firmware Analysis Admin, Guest Configuration Resource Contributor, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Data Access Administrator (preview), Key Vault Reader, Key Vault Secrets Officer, Kubernetes Extension Contributor, Lab Assistant, Lab Contributor, Lab Creator, Lab Operator, Lab Services Contributor, Lab Services Reader, Load Test Contributor, Load Test Owner, Load Test Reader, LocalNGFirewallAdministrator role, LocalRulestacksAdministrator role, Log Analytics Contributor, Logic App Contributor, Managed Application Contributor Role, Managed Applications Reader, Managed Identity Contributor, Managed Identity Operator, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, Microsoft Sentinel Contributor, Microsoft Sentinel Reader, Microsoft Sentinel Responder, Network Contributor, New Relic APM Account Contributor, PlayFab Contributor, Private DNS Zone Contributor, Quota Request Operator, Redis Cache Contributor, Resource Policy Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Services Hub Operator, SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Tag Contributor, Template Spec Contributor, Traffic Manager Contributor, Web Plan Contributor, Website Contributor
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups. API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , App Compliance Automation Administrator, App Compliance Automation Reader, Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Contributor, Automation Job Operator, Automation Operator, Automation Runbook Operator, Autonomous Development Platform Data Contributor (Preview), Autonomous Development Platform Data Owner (Preview), Autonomous Development Platform Data Reader (Preview), Avere Contributor, Avere Operator, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Arc ScVmm Administrator role, Azure Arc ScVmm Private Cloud User, Azure Arc ScVmm Private Clouds Onboarding, Azure Arc ScVmm VM Contributor, Azure Arc VMware Administrator role , Azure Arc VMware Private Cloud User, Azure Arc VMware Private Clouds Onboarding, Azure Arc VMware VM Contributor, Azure Center for SAP solutions administrator, Azure Center for SAP solutions reader, Azure Center for SAP solutions service role, Azure Front Door Domain Contributor, Azure Front Door Domain Reader, Azure Front Door Secret Contributor, Azure Front Door Secret Reader, Azure Kubernetes Fleet Manager RBAC Admin, Azure Kubernetes Fleet Manager RBAC Cluster Admin, Azure Kubernetes Fleet Manager RBAC Reader, Azure Kubernetes Fleet Manager RBAC Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Maps Contributor, Azure Sphere Contributor, Azure Sphere Publisher, Azure Sphere Reader, Azure Stack HCI registration role, Backup Contributor, Backup Operator, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Chamber Admin, Chamber User, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Code Signing Certificate Profile Signer, Cognitive Services Contributor, Cognitive Services User, Collaborative Data Contributor, Collaborative Runtime Operator, ContainerApp Reader, Cosmos DB Account Reader Role, Cosmos DB Operator, Cost Management Contributor, Cost Management Reader, Data Boundary Tenant Administrator, Data Box Contributor, Data Factory Contributor, Data Lake Analytics Developer, Deployment Environments User, Desktop Virtualization Application Group Contributor, Desktop Virtualization Application Group Reader, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Host Pool Reader, Desktop Virtualization Power On Contributor, Desktop Virtualization Power On Off Contributor, Desktop Virtualization Reader, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Virtual Machine Contributor, Desktop Virtualization Workspace Contributor, Desktop Virtualization Workspace Reader, DevCenter Dev Box User, DevCenter Project Admin, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DevTest Labs User, Disk Pool Operator, Disk Restore Operator, Disk Snapshot Contributor, DNS Resolver Contributor, DNS Zone Contributor, DocumentDB Account Contributor, Domain Services Contributor, Domain Services Reader, Elastic SAN Owner, Elastic SAN Reader, Elastic SAN Snapshot Exporter, Elastic SAN Volume Importer, EventGrid Contributor, EventGrid Data Sender, EventGrid EventSubscription Contributor, EventGrid EventSubscription Reader, Experimentation Administrator, Experimentation Contributor, Firmware Analysis Admin, HDInsight Cluster Operator, HDInsight on AKS Cluster Admin, HDInsight on AKS Cluster Pool Admin, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Data Access Administrator (preview), Key Vault Reader, Key Vault Secrets Officer, Kubernetes Cluster - Azure Arc Onboarding, Kubernetes Extension Contributor, Lab Assistant, Lab Contributor, Lab Creator, Lab Operator, Lab Services Contributor, Lab Services Reader, Load Test Contributor, Load Test Owner, Load Test Reader, LocalNGFirewallAdministrator role, LocalRulestacksAdministrator role, Logic App Contributor, Logic App Operator, Logic Apps Standard Contributor (Preview), Logic Apps Standard Developer (Preview), Logic Apps Standard Operator (Preview), Logic Apps Standard Reader (Preview), Managed Identity Contributor, Managed Identity Operator, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, Microsoft Sentinel Contributor, Microsoft Sentinel Reader, Microsoft Sentinel Responder, Monitoring Metrics Publisher, MySQL Backup And Export Operator, Network Contributor, New Relic APM Account Contributor, PlayFab Contributor, PlayFab Reader, PostgreSQL Flexible Server Long Term Retention Backup Role, Private DNS Zone Contributor, Procurement Contributor, Quota Request Operator, Redis Cache Contributor, Reservation Purchaser, SaaS Hub Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Security Reader, Services Hub Operator, SignalR AccessKey Reader, SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Backup Contributor, Storage Account Contributor, Support Request Contributor, Tag Contributor, Template Spec Contributor, Traffic Manager Contributor, Web Plan Contributor, Website Contributor, Windows 365 Network Interface Contributor
Microsoft.SerialConsole/serialPorts/connect/actionConnect to a serial port none
Microsoft.SqlVirtualMachine/*no description given none
Microsoft.Storage/storageAccounts/listKeys/actionReturns the access keys for the specified storage account. App Compliance Automation Administrator, DevTest Labs User, Disk Snapshot Contributor , Log Analytics Contributor, Logic App Contributor, Reader and Data Access, SqlMI Migration Role, SqlVM Migration Role, Storage Account Key Operator Service Role
Microsoft.Storage/storageAccounts/readReturns the list of storage accounts or gets the properties for the specified storage account. App Compliance Automation Administrator, App Compliance Automation Reader, Azure Center for SAP solutions administrator , Azure Center for SAP solutions reader, Azure Center for SAP solutions service role, Backup Contributor, Backup Operator, Desktop Virtualization Virtual Machine Contributor, Disk Snapshot Contributor, Logic App Contributor, Reader and Data Access, Site Recovery Contributor, Site Recovery Operator, SqlMI Migration Role, SqlVM Migration Role, Storage Account Backup Contributor
Microsoft.Support/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Contributor, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Backup Contributor, Backup Operator, Billing Reader, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Cognitive Services User, Collaborative Data Contributor, Collaborative Runtime Operator, Cosmos DB Account Reader Role, Cosmos DB Operator, Cost Management Contributor, Cost Management Reader, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Application Group Reader, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Host Pool Reader, Desktop Virtualization Reader, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Workspace Contributor, Desktop Virtualization Workspace Reader, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid Contributor, EventGrid EventSubscription Contributor, HDInsight Cluster Operator, Integration Service Environment Contributor, Integration Service Environment Developer, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Data Access Administrator (preview), Key Vault Reader, Key Vault Secrets Officer, Kubernetes Cluster - Azure Arc Onboarding, Lab Creator, LocalNGFirewallAdministrator role, LocalRulestacksAdministrator role, Log Analytics Contributor, Log Analytics Reader, Logic App Contributor, Logic App Operator, Logic Apps Standard Contributor (Preview), Logic Apps Standard Developer (Preview), Logic Apps Standard Operator (Preview), Logic Apps Standard Reader (Preview), Managed Identity Contributor, Managed Identity Operator, Microsoft Sentinel Contributor, Microsoft Sentinel Reader, Microsoft Sentinel Responder, Monitoring Contributor, Monitoring Metrics Publisher, Monitoring Reader, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Quota Request Operator, Redis Cache Contributor, Resource Policy Contributor, Role Based Access Control Administrator (Preview), Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), SignalR AccessKey Reader, SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, User Access Administrator, Web Plan Contributor, Website Contributor
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in Policy
Policy DisplayName Policy Id Category State
[Preview]: Configure ChangeTracking Extension for Linux virtual machine scale sets 1288c8d7-4b05-4e3a-bc88-9053caefc021 Security Center Preview
[Preview]: Configure ChangeTracking Extension for Linux virtual machines ec88097d-843f-4a92-8471-78016d337ba4 Security Center Preview
[Preview]: Configure ChangeTracking Extension for Windows virtual machine scale sets 4bb303db-d051-4099-95d2-e3e1428a4d2c Security Center Preview
[Preview]: Configure ChangeTracking Extension for Windows virtual machines f08f556c-12ff-464d-a7de-40cb5b6cccec Security Center Preview
[Preview]: Configure Linux VMs to install AMA for ChangeTracking and Inventory with user-assigned managed identity 56d0ed2b-60fc-44bf-af81-a78c851b5fe1 ChangeTrackingAndInventory Preview
[Preview]: Configure Linux VMSS to install AMA for ChangeTracking and Inventory with user-assigned managed identity b73e81f3-6303-48ad-9822-b69fc00c15ef ChangeTrackingAndInventory Preview
[Preview]: Configure SQL Virtual Machines to automatically install Azure Monitor Agent f91991d1-5383-4c95-8ee5-5ac423dd8bb1 Security Center Preview
[Preview]: Configure supported Linux virtual machine scale sets to automatically install the Azure Security agent 6654c8c4-e6f8-43f8-8869-54327af7ce32 Security Center Preview
[Preview]: Configure supported Linux virtual machine scale sets to automatically install the Guest Attestation extension 57c2e3f0-98cf-4c3b-aa6b-e8f70726e74e Security Center Preview
[Preview]: Configure supported Linux virtual machines to automatically enable Secure Boot 95406fc3-1f69-47b0-8105-4c03b276ec5c Security Center Preview
[Preview]: Configure supported Linux virtual machines to automatically install the Azure Security agent 5f8eb305-9c9f-4abe-9bb0-df220d9faba2 Security Center Preview
[Preview]: Configure supported Linux virtual machines to automatically install the Guest Attestation extension 6074e9a3-c711-4856-976d-24d51f9e065b Security Center Preview
[Preview]: Configure supported virtual machines to automatically enable vTPM e494853f-93c3-4e44-9210-d12f61a64b34 Security Center Preview
[Preview]: Configure supported Windows machines to automatically install the Azure Security agent 1537496a-b1e8-482b-a06a-1cc2415cdc7b Security Center Preview
[Preview]: Configure supported Windows virtual machine scale sets to automatically install the Azure Security agent 808a7dc4-49f2-4e7b-af75-d14e561c244a Security Center Preview
[Preview]: Configure supported Windows virtual machine scale sets to automatically install the Guest Attestation extension c9b2ae08-09e2-4f0e-bb43-b60bf0135bdf Security Center Preview
[Preview]: Configure supported Windows virtual machines to automatically enable Secure Boot 7cb1b219-61c6-47e0-b80c-4472cadeeb5f Security Center Preview
[Preview]: Configure supported Windows virtual machines to automatically install the Guest Attestation extension 98ea2fc7-6fc6-4fd1-9d8d-6331154da071 Security Center Preview
[Preview]: Configure system-assigned managed identity to enable Azure Monitor assignments on VMs 17b3de92-f710-4cf4-aa55-0e7859f1ed7b Monitoring Preview
[Preview]: Configure VMs created with Shared Image Gallery images to install the Guest Attestation extension 496e010e-fa91-4c00-be4b-92b481f67b58 Security Center Preview
[Preview]: Configure VMSS created with Shared Image Gallery images to install the Guest Attestation extension 009259b0-12e8-42c9-94e7-7af86aa58d13 Security Center Preview
[Preview]: Configure Windows VMs to install AMA for ChangeTracking and Inventory with user-assigned managed identity ad1eeff9-20d7-4c82-a04e-903acab0bfc1 ChangeTrackingAndInventory Preview
[Preview]: Configure Windows VMSS to install AMA for ChangeTracking and Inventory with user-assigned managed identity 4485d24b-a9d3-4206-b691-1fad83bc5007 ChangeTrackingAndInventory Preview
Configure backup on virtual machines with a given tag to a new recovery services vault with a default policy 83644c87-93dd-49fe-bf9f-6aff8fd0834e Backup GA
Configure backup on virtual machines with a given tag to an existing recovery services vault in the same location 345fa903-145c-4fe1-8bcd-93ec2adccde8 Backup GA
Configure backup on virtual machines without a given tag to a new recovery services vault with a default policy 98d0b9f8-fd90-49c9-88e2-d3baf3b0dd86 Backup GA
Configure backup on virtual machines without a given tag to an existing recovery services vault in the same location 09ce66bc-1220-4153-8104-e3f51c936913 Backup GA
Configure Linux virtual machine scale sets to run Azure Monitor Agent with system-assigned managed identity-based authentication 56a3e4f8-649b-4fac-887e-5564d11e8d3a Monitoring GA
Configure Linux virtual machine scale sets to run Azure Monitor Agent with user-assigned managed identity-based authentication 59c3d93f-900b-4827-a8bd-562e7b956e7c Monitoring GA
Configure Linux virtual machines to run Azure Monitor Agent with system-assigned managed identity-based authentication a4034bc6-ae50-406d-bf76-50f4ee5a7811 Monitoring GA
Configure Linux virtual machines to run Azure Monitor Agent with user-assigned managed identity-based authentication ae8a10e6-19d6-44a3-a02d-a2bdfc707742 Monitoring GA
Configure periodic checking for missing system updates on azure virtual machines 59efceea-0c96-497e-a4a1-4eb2290dac15 Azure Update Manager GA
Configure Windows virtual machine scale sets to run Azure Monitor Agent using system-assigned managed identity 4efbd9d8-6bc6-45f6-9be2-7fe9dd5d89ff Monitoring GA
Configure Windows virtual machine scale sets to run Azure Monitor Agent with user-assigned managed identity-based authentication 98569e20-8f32-4f31-bf34-0e91590ae9d3 Monitoring GA
Configure Windows virtual machines to run Azure Monitor Agent using system-assigned managed identity ca817e41-e85a-4783-bc7f-dc532d36235e Monitoring GA
Configure Windows virtual machines to run Azure Monitor Agent with user-assigned managed identity-based authentication 637125fd-7c39-4b94-bb0a-d331faf333a9 Monitoring GA
Deploy - Configure Dependency agent to be enabled on Windows virtual machine scale sets 3be22e3b-d919-47aa-805e-8985dbeb0ad9 Monitoring GA
Deploy - Configure Log Analytics extension to be enabled on Windows virtual machine scale sets 3c1b3629-c8f8-4bf6-862c-037cb9094038 Monitoring GA
Deploy default Microsoft IaaSAntimalware extension for Windows Server 2835b622-407b-4114-9198-6f7064cbe0dc Compute GA
Deploy Dependency agent for Linux virtual machine scale sets 765266ab-e40e-4c61-bcb2-5a5275d0b7c0 Monitoring GA
Deploy Dependency agent for Linux virtual machine scale sets with Azure Monitoring Agent settings 2fea0c12-e7d4-4e03-b7bf-c34b2b8d787d Monitoring GA
Deploy Dependency agent to be enabled on Windows virtual machine scale sets with Azure Monitoring Agent settings af0082fd-fa58-4349-b916-b0e47abb0935 Monitoring GA
Deploy Log Analytics extension for Linux virtual machine scale sets. See deprecation notice below 5ee9e9ed-0b42-41b7-8c9c-3cfb2fbe2069 Monitoring GA
JSON