last sync: 2025-Oct-23 17:22:49 UTC

Azure Resilience Management Goals Administrator

Azure BuiltIn RBAC Role definition

NameAzure Resilience Management Goals Administrator
Ida2b7cc47-30ec-462f-a2f4-9ac6e1c266af
DescriptionThis role allows users to view, assign and delete resiliency goals for the service group, as well as modify the list of service group members that get evaluated against the goal. This role also allows a user to assign goal related permissions to other users.
CategoryNone
CreatedOn2025-10-20 15:12:57 UTC
UpdatedOn2025-10-20 15:12:57 UTC
Permissions summary Effective control plane and data plane operations: 45 (unique operations)
•action: 2
•delete: 2
•read: 38
•write: 3

Actions: 9
Resolved control plane operations from Actions: 45
Effective control plane operations: 45
•action: 2
•delete: 2
•read: 38
•write: 3

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 17331

DataActions: 0
Resolved data plane operations: 0
Effective data plane operations: 0

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 4081
Actions
Operation Description
Microsoft.Authorization/*/readwildcarded / no description
Microsoft.Authorization/roleAssignments/writeCreate a role assignment at the specified scope.
Microsoft.AzureResilienceManagement/goalAssignments/*wildcarded / no description
Microsoft.AzureResilienceManagement/goalAssignments/goalResources/*wildcarded / no description
Microsoft.AzureResilienceManagement/goalTemplates/*wildcarded / no description
Microsoft.AzureResilienceManagement/locations/operationStatuses/readread OperationStatuses
Microsoft.AzureResilienceManagement/operations/readread operations
Microsoft.Management/ServiceGroups/readRead a Service Group
Microsoft.Relationships/ServiceGroupMember/readRead a 'ServiceGroupMember' Relationship
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in
BuiltIn Policy
none
History
Date/Time (UTC ymd) (i) Change Change detail
2025-10-20 17:22:40 add: Role a2b7cc47-30ec-462f-a2f4-9ac6e1c266af
JSON
api-version=2023-07-01-preview
Condition
    @Resource[HasObotoken] boolequals true &&
    (
        @Request[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals  {
        de754d53-652d-4c75-a67f-1e48d8b49c97 (Service Group Reader),
        acdd72a7-3385-48ef-bd42-f606fba81ae7 (Reader),
        b0d8363b-8ddd-447d-831f-62ca05bff136 (Monitoring Data Reader),
        b24988ac-6180-42a0-ab88-20f7382dd24c (Contributor),
        7c2e40b7-25eb-482a-82cb-78ba06cb46d5 (Chaos Studio Experiment Contributor)
        }
    )