last sync: 2023-Jun-07 17:44:45 UTC

Azure RBAC Role definition

Azure Connected Machine Resource Administrator

NameAzure Connected Machine Resource Administrator
Microsoft docs
Idcd570a14-e51a-42ad-bac8-bafd67325302
DescriptionCan read, write, delete and re-onboard Azure Connected Machines.
CreatedOn2019-10-23 20:24:59 UTC
UpdatedOn2021-12-15 16:10:25 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2021-12-15 17:18:05 change: Actions Actions: 'add Microsoft.Resources/deployments/*'
2021-06-09 16:50:31 change: Actions Actions: 'add Microsoft.HybridCompute/machines/UpgradeExtensions/action'
2021-04-29 16:55:26 change: Actions Actions: 'add Microsoft.HybridCompute/machines/extensions/read; add Microsoft.HybridCompute/machines/extensions/delete'
2021-03-24 14:32:47 change: Actions Actions: 'remove Microsoft.HybridCompute/machines/reconnect/action; add Microsoft.HybridCompute/privateLinkScopes/*'
2019-10-24 02:15:32 add: Role cd570a14-e51a-42ad-bac8-bafd67325302
Actions
Operation Description Used in other Roles
Microsoft.HybridCompute/*/readno description given Azure Connected Machine Resource Manager, Hybrid Server Resource Administrator
Microsoft.HybridCompute/machines/deleteDeletes an Azure Arc machines Azure Connected Machine Resource Manager
Microsoft.HybridCompute/machines/extensions/deleteDeletes an Azure Arc extensions Azure Connected Machine Resource Manager
Microsoft.HybridCompute/machines/extensions/readReads any Azure Arc extensions Azure Connected Machine Resource Manager
Microsoft.HybridCompute/machines/extensions/writeInstalls or Updates an Azure Arc extensions Azure Connected Machine Resource Manager, Azure Extension for SQL Server Deployment, Log Analytics Contributor
Microsoft.HybridCompute/machines/readRead any Azure Arc machines Azure Connected Machine Onboarding, Azure Connected Machine Resource Manager, Hybrid Server Onboarding
Microsoft.HybridCompute/machines/UpgradeExtensions/actionUpgrades Extensions on Azure Arc machines Azure Connected Machine Resource Manager, Windows Admin Center Administrator Login
Microsoft.HybridCompute/machines/writeWrites an Azure Arc machines Azure Connected Machine Onboarding, Azure Connected Machine Resource Manager, Hybrid Server Onboarding
Microsoft.HybridCompute/privateLinkScopes/*no description given none
Microsoft.Resources/deployments/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Contributor, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Center for SAP solutions administrator, Azure Center for SAP solutions reader, Azure Center for SAP solutions service role, Azure Kubernetes Fleet Manager Contributor Role, Azure Kubernetes Service Contributor Role, Azure Kubernetes Service Policy Add-on Deployment, Azure Maps Contributor, Azure Sphere Contributor, Backup Contributor, Backup Operator, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Chamber Admin, Chamber User, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Code Signing Certificate Profile Signer, Cognitive Services Contributor, Collaborative Data Contributor, Collaborative Runtime Operator, ContainerApp Reader, Cosmos DB Operator, Data Box Contributor, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Power On Contributor, Desktop Virtualization Power On Off Contributor, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Virtual Machine Contributor, Desktop Virtualization Workspace Contributor, DevCenter Project Admin, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, Disk Pool Operator, DNS Resolver Contributor, DNS Zone Contributor, DocumentDB Account Contributor, Elastic SAN Owner, EventGrid Contributor, EventGrid EventSubscription Contributor, Guest Configuration Resource Contributor, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Kubernetes Extension Contributor, Lab Assistant, Lab Contributor, Lab Creator, Lab Operator, Lab Services Contributor, Lab Services Reader, Load Test Contributor, Load Test Owner, Load Test Reader, LocalNGFirewallAdministrator role, LocalRulestacksAdministrator role, Log Analytics Contributor, Logic App Contributor, Managed Application Contributor Role, Managed Applications Reader, Managed Identity Contributor, Managed Identity Operator, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, Microsoft Sentinel Contributor, Microsoft Sentinel Reader, Microsoft Sentinel Responder, Network Contributor, New Relic APM Account Contributor, PlayFab Contributor, Private DNS Zone Contributor, Quota Request Operator, Redis Cache Contributor, Resource Policy Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Services Hub Operator, SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Tag Contributor, Template Spec Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in Policy
Policy DisplayName Policy Id Category State
[Preview]: Configure ChangeTracking Extension for Linux Arc machines 10caed8a-652c-4d1d-84e4-2805b7c07278 Security Center Preview
[Preview]: Configure ChangeTracking Extension for Windows Arc machines 4bb303db-d051-4099-95d2-e3e1428a4cd5 Security Center Preview
[Preview]: Configure Linux Arc-enabled machines to to install AMA for ChangeTracking and Inventory 09a1f130-7697-42bc-8d84-8a9ea17e5187 ChangeTrackingAndInventory Preview
[Preview]: Configure periodic checking for missing system updates on azure Arc-enabled servers bfea026e-043f-4ff4-9d1b-bf301ca7ff46 Update Management Center Preview
[Preview]: Configure Windows Arc-enabled machines to install AMA for ChangeTracking and Inventory a7acfae7-9497-4a3f-a3b5-a16a50abbe2f ChangeTrackingAndInventory Preview
Configure Azure Arc Private Link Scopes to disable public network access de0bc8ea-76e2-4fe2-a288-a07556d0e9c4 Azure Arc GA
Configure Azure Arc Private Link Scopes with private endpoints d6eeba80-df61-4de5-8772-bc1b7852ba6b Azure Arc GA
Configure Azure Arc-enabled servers to use an Azure Arc Private Link Scope a3461c8c-6c9d-4e42-a644-40ba8a1abf49 Azure Arc GA
Configure Linux Arc-enabled machines to run Azure Monitor Agent 845857af-0333-4c5d-bbbc-6076697da122 Monitoring GA
Configure Windows Arc-enabled machines to run Azure Monitor Agent 94f686d6-9a24-4e19-91f1-de937dc171a4 Monitoring GA
JSON