Name | Azure Stack HCI Administrator | |||||||||||||||||||||
Id | bda0d508-adf1-4af0-9c28-88919fc3ae06 | |||||||||||||||||||||
Description | Grants full access to the cluster and its resources, including the ability to register Azure Stack HCI and assign others as Azure Arc HCI VM Contributor and/or Azure Arc HCI VM Reader | |||||||||||||||||||||
CreatedOn | 2023-02-03 05:08:48 UTC | |||||||||||||||||||||
UpdatedOn | 2024-08-08 05:12:21 UTC | |||||||||||||||||||||
History |
|
|||||||||||||||||||||
Permissions summary | Effective control plane and data plane operations: 215 (unique operations) •Action: 50 •delete: 31 •read: 101 •write: 33 Actions: 96 Resolved control plane operations from Actions: 215 Effective control plane operations: 215 •Action: 50 •delete: 31 •read: 101 •write: 33 NotActions: 0 Resolved control plane operations from NotActions: 0 Effective denied control plane operations: 15977 DataActions: 0 Resolved data plane operations: 0 Effective data plane operations: 0 NotDataActions: 0 Resolved data plane operations from NotDataActions: 0 Effective denied data plane operations: 3303 |
|||||||||||||||||||||
Actions | ||||||||||||||||||||||
NotActions | n/a | |||||||||||||||||||||
DataActions | n/a | |||||||||||||||||||||
NotDataActions | n/a | |||||||||||||||||||||
Used in BuiltIn Policy |
none | |||||||||||||||||||||
JSON |
|
|||||||||||||||||||||
Condition |
( ( ! ( ActionMatches { 'Microsoft.Authorization/roleAssignments/write' } ) ) OR ( @Request[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals { f5819b54-e033-4d82-ac66-4fec3cbf3f4c (Azure Connected Machine Resource Manager), cd570a14-e51a-42ad-bac8-bafd67325302 (Azure Connected Machine Resource Administrator), b64e21ea-ac4e-4cdf-9dc9-5b892992bee7 (Azure Connected Machine Onboarding), 4b3fe76c-f777-4d24-a2d7-b027b0f7b273 (Azure Stack HCI VM Reader), 874d1c73-6003-4e60-a13a-cb31ea190a85 (Azure Stack HCI VM Contributor), 865ae368-6a45-4bd1-8fbf-0d5151f56fc1 (Azure Stack HCI Device Management Role), 7b1f81f9-4196-4058-8aae-762e593270df (Azure Resource Bridge Deployment Role), 4633458b-17de-408a-b874-0445c86b69e6 (Key Vault Secrets User), c99c945f-8bd1-4fb1-a903-01460aae6068 (Azure Stack HCI Connected InfraVMs) } ) ) AND ( ( ! ( ActionMatches { 'Microsoft.Authorization/roleAssignments/delete' } ) ) OR ( @Resource[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals { f5819b54-e033-4d82-ac66-4fec3cbf3f4c (Azure Connected Machine Resource Manager), cd570a14-e51a-42ad-bac8-bafd67325302 (Azure Connected Machine Resource Administrator), b64e21ea-ac4e-4cdf-9dc9-5b892992bee7 (Azure Connected Machine Onboarding), 4b3fe76c-f777-4d24-a2d7-b027b0f7b273 (Azure Stack HCI VM Reader), 874d1c73-6003-4e60-a13a-cb31ea190a85 (Azure Stack HCI VM Contributor), 865ae368-6a45-4bd1-8fbf-0d5151f56fc1 (Azure Stack HCI Device Management Role), 7b1f81f9-4196-4058-8aae-762e593270df (Azure Resource Bridge Deployment Role), 4633458b-17de-408a-b874-0445c86b69e6 (Key Vault Secrets User), c99c945f-8bd1-4fb1-a903-01460aae6068 (Azure Stack HCI Connected InfraVMs) } ) ) |