last sync: 2025-Apr-29 17:15:48 UTC

Kubernetes Agent Subscription Level Operator

Azure BuiltIn RBAC Role definition

NameKubernetes Agent Subscription Level Operator
Idada52afe-776a-4b4d-a8f2-55670d3d8178
DescriptionGrants Microsoft Defender for Cloud subscription level permissions needed to activate Containers plan
CategoryNone
CreatedOn2024-11-14 10:01:45 UTC
UpdatedOn2024-12-12 11:16:08 UTC
Permissions summary Effective control plane and data plane operations: 55 (unique operations)
•Action: 9
•Delete: 2
•read: 40
•Write: 4

Actions: 12
Resolved control plane operations from Actions: 55
Effective control plane operations: 55
•Action: 9
•Delete: 2
•read: 40
•Write: 4

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 16435

DataActions: 0
Resolved data plane operations: 0
Effective data plane operations: 0

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3371
Actions
Operation Description
Microsoft.Authorization/*/readwildcarded / no description
Microsoft.Insights/alertRules/*wildcarded / no description
Microsoft.OperationalInsights/workspaces/listKeys/actionRetrieves the list keys for the workspace. These keys are used to connect Microsoft Operational Insights agents to the workspace.
Microsoft.OperationalInsights/workspaces/readGets an existing workspace
Microsoft.OperationalInsights/workspaces/sharedkeys/actionRetrieves the shared keys for the workspace. These keys are used to connect Microsoft Operational Insights agents to the workspace.
Microsoft.OperationalInsights/workspaces/sharedkeys/readRetrieves the shared keys for the workspace. These keys are used to connect Microsoft Operational Insights agents to the workspace.
Microsoft.OperationalInsights/workspaces/writeCreates a new workspace or links to an existing workspace by providing the customer id from the existing workspace.
Microsoft.Resources/deployments/*wildcarded / no description
Microsoft.Resources/subscriptions/operationresults/readGet the subscription operation results.
Microsoft.Resources/subscriptions/readGets the list of subscriptions.
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups.
Microsoft.Resources/subscriptions/resourceGroups/writeCreates or updates a resource group.
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in
BuiltIn Policy
none
History
Date/Time (UTC ymd) (i) Change Change detail
2024-12-12 18:54:41 change: Actions Actions: 'add Microsoft.Resources/subscriptions/resourceGroups/write'
2024-12-05 18:53:40 change: Actions Actions: 'add Microsoft.Authorization/*/read; add Microsoft.Insights/alertRules/*; add Microsoft.Resources/deployments/*; add Microsoft.Resources/subscriptions/resourceGroups/read; add Microsoft.Resources/subscriptions/operationresults/read; add Microsoft.Resources/subscriptions/read'
2024-11-14 18:51:40 add: Role ada52afe-776a-4b4d-a8f2-55670d3d8178
JSON
api-version=2023-07-01-preview
Condition none