Name | Azure Stack HCI Administrator Microsoft Learn | ||||||||||||||||||||||||
Id | bda0d508-adf1-4af0-9c28-88919fc3ae06 | ||||||||||||||||||||||||
Description | Grants full access to the cluster and its resources, including the ability to register Azure Stack HCI and assign others as Azure Arc HCI VM Contributor and/or Azure Arc HCI VM Reader | ||||||||||||||||||||||||
Category | Hybrid + multicloud Microsoft Learn | ||||||||||||||||||||||||
CreatedOn | 2023-02-03 05:08:48 UTC | ||||||||||||||||||||||||
UpdatedOn | 2025-01-30 17:46:12 UTC | ||||||||||||||||||||||||
Permissions summary | Effective control plane and data plane operations: 240 (unique operations) •Action: 56 •delete: 36 •read: 110 •write: 38 Actions: 98 Resolved control plane operations from Actions: 240 Effective control plane operations: 240 •Action: 56 •delete: 36 •read: 110 •write: 38 NotActions: 0 Resolved control plane operations from NotActions: 0 Effective denied control plane operations: 16250 DataActions: 0 Resolved data plane operations: 0 Effective data plane operations: 0 NotDataActions: 0 Resolved data plane operations from NotDataActions: 0 Effective denied data plane operations: 3371 |
||||||||||||||||||||||||
Actions | |||||||||||||||||||||||||
NotActions | n/a | ||||||||||||||||||||||||
DataActions | n/a | ||||||||||||||||||||||||
NotDataActions | n/a | ||||||||||||||||||||||||
Used in BuiltIn Policy |
none | ||||||||||||||||||||||||
History |
|
||||||||||||||||||||||||
JSON |
|
||||||||||||||||||||||||
Condition |
( ( ! ( ActionMatches { 'Microsoft.Authorization/roleAssignments/write' } ) ) OR ( @Request[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals { f5819b54-e033-4d82-ac66-4fec3cbf3f4c (Azure Connected Machine Resource Manager), cd570a14-e51a-42ad-bac8-bafd67325302 (Azure Connected Machine Resource Administrator), b64e21ea-ac4e-4cdf-9dc9-5b892992bee7 (Azure Connected Machine Onboarding), 4b3fe76c-f777-4d24-a2d7-b027b0f7b273 (Azure Stack HCI VM Reader), 874d1c73-6003-4e60-a13a-cb31ea190a85 (Azure Stack HCI VM Contributor), 865ae368-6a45-4bd1-8fbf-0d5151f56fc1 (Azure Stack HCI Device Management Role), 7b1f81f9-4196-4058-8aae-762e593270df (Azure Resource Bridge Deployment Role), 4633458b-17de-408a-b874-0445c86b69e6 (Key Vault Secrets User), c99c945f-8bd1-4fb1-a903-01460aae6068 (Azure Stack HCI Connected InfraVMs) } ) ) AND ( ( ! ( ActionMatches { 'Microsoft.Authorization/roleAssignments/delete' } ) ) OR ( @Resource[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals { f5819b54-e033-4d82-ac66-4fec3cbf3f4c (Azure Connected Machine Resource Manager), cd570a14-e51a-42ad-bac8-bafd67325302 (Azure Connected Machine Resource Administrator), b64e21ea-ac4e-4cdf-9dc9-5b892992bee7 (Azure Connected Machine Onboarding), 4b3fe76c-f777-4d24-a2d7-b027b0f7b273 (Azure Stack HCI VM Reader), 874d1c73-6003-4e60-a13a-cb31ea190a85 (Azure Stack HCI VM Contributor), 865ae368-6a45-4bd1-8fbf-0d5151f56fc1 (Azure Stack HCI Device Management Role), 7b1f81f9-4196-4058-8aae-762e593270df (Azure Resource Bridge Deployment Role), 4633458b-17de-408a-b874-0445c86b69e6 (Key Vault Secrets User), c99c945f-8bd1-4fb1-a903-01460aae6068 (Azure Stack HCI Connected InfraVMs) } ) ) |