last sync: 2025-Apr-29 17:15:48 UTC

AVS Orchestrator Role

Azure BuiltIn RBAC Role definition

NameAVS Orchestrator Role
Idd715fb95-a0f0-4f1c-8be6-5ad2d2767f67
DescriptionDo not remove this role from your resource group because it is critical to enable your AVS private cloud to operate. If the role is removed, it will cause your AVS private cloud control plane to no longer operate correctly. The role is used to enable the AVS private cloud control plane to create the supporting resources in the resource group of the private clouds attached virtual network and bind them to the attached virtual network. This role is not intended for use cases outside of assignment to the associated AVS identity in your entra-id tenant.
CategoryNone
CreatedOn2024-08-27 15:13:33 UTC
UpdatedOn2025-02-13 20:38:23 UTC
Permissions summary Effective control plane and data plane operations: 56 (unique operations)
•action: 8
•delete: 13
•read: 20
•write: 15

Actions: 58
Resolved control plane operations from Actions: 56
Effective control plane operations: 56
•action: 8
•delete: 13
•read: 20
•write: 15

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 16434

DataActions: 0
Resolved data plane operations: 0
Effective data plane operations: 0

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3371
Actions
Operation Description
Microsoft.Authorization/roleAssignments/delete conditionedDelete a role assignment at the specified scope.
Microsoft.Authorization/roleAssignments/readGet information about a role assignment.
Microsoft.Network/locations/operationResults/readGets operation result of an async POST or DELETE operation
Microsoft.Network/locations/operations/readGets operation resource that represents status of an asynchronous operation
Microsoft.Network/networkIntentPolicies/deleteDeletes an Network Intent Policy
Microsoft.Network/networkIntentPolicies/readGets an Network Intent Policy Description
Microsoft.Network/networkIntentPolicies/writeCreates an Network Intent Policy or updates an existing Network Intent Policy
Microsoft.Network/networkInterfaces/deleteDeletes a network interface
Microsoft.Network/networkInterfaces/join/actionJoins a Virtual Machine to a network interface. Not Alertable.
Microsoft.Network/networkInterfaces/readGets a network interface definition.
Microsoft.Network/networkInterfaces/writeCreates a network interface or updates an existing network interface.
Microsoft.Network/networkSecurityGroups/deleteDeletes a network security group
Microsoft.Network/networkSecurityGroups/join/actionJoins a network security group. Not Alertable.
Microsoft.Network/networkSecurityGroups/readGets a network security group definition
Microsoft.Network/networkSecurityGroups/securityRules/deleteDeletes a security rule
Microsoft.Network/networkSecurityGroups/securityRules/readGets a security rule definition
Microsoft.Network/networkSecurityGroups/securityRules/readGets a security rule definition
Microsoft.Network/networkSecurityGroups/securityRules/writeCreates a security rule or updates an existing security rule
Microsoft.Network/networkSecurityGroups/writeCreates a network security group or updates an existing network security group
Microsoft.Network/publicIPAddresses/deleteDeletes a public Ip address.
Microsoft.Network/publicIPAddresses/readGets a public ip address definition.
Microsoft.Network/publicIPAddresses/writeCreates a public Ip address or updates an existing public Ip address.
Microsoft.Network/routeTables/deleteDeletes a route table definition
Microsoft.Network/routeTables/join/actionJoins a route table. Not Alertable.
Microsoft.Network/routeTables/readGets a route table definition
Microsoft.Network/routeTables/routes/deleteDeletes a route definition
Microsoft.Network/routeTables/routes/readGets a route definition
Microsoft.Network/routeTables/routes/writeCreates a route or Updates an existing route
Microsoft.Network/routeTables/writeCreates a route table or Updates an existing rotue table
Microsoft.Network/virtualHubs/bgpConnections/readGets a Hub Bgp Connection child resource of Virtual Hub
Microsoft.Network/virtualHubs/bgpConnections/writeCreates or Updates a Hub Bgp Connection child resource of Virtual Hub
Microsoft.Network/virtualHubs/deleteDeletes a Virtual Hub
Microsoft.Network/virtualHubs/ipConfigurations/readGets a Hub IpConfiguration child resource of Virtual Hub
Microsoft.Network/virtualHubs/ipConfigurations/writeCreates or Updates a Hub IpConfiguration child resource of Virtual Hub
Microsoft.Network/virtualHubs/writeCreate or update a Virtual Hub
Microsoft.Network/virtualNetworks/join/actionJoins a virtual network. Not Alertable.
Microsoft.Network/virtualNetworks/peer/actionPeers a virtual network with another virtual network
Microsoft.Network/virtualNetworks/readGet the virtual network definition
Microsoft.Network/virtualNetworks/subnets/deleteDeletes a virtual network subnet
Microsoft.Network/virtualNetworks/subnets/join/actionJoins a virtual network. Not Alertable.
Microsoft.Network/virtualNetworks/subnets/prepareNetworkPolicies/actionPrepares a subnet by applying necessary Network Policies
Microsoft.Network/virtualNetworks/subnets/readGets a virtual network subnet definition
Microsoft.Network/virtualNetworks/subnets/serviceAssociationLinks/deleteno description given
Microsoft.Network/virtualNetworks/subnets/serviceAssociationLinks/deleteno description given
Microsoft.Network/virtualNetworks/subnets/serviceAssociationLinks/readno description given
Microsoft.Network/virtualNetworks/subnets/serviceAssociationLinks/writeno description given
Microsoft.Network/virtualNetworks/subnets/unprepareNetworkPolicies/actionUnprepare a subnet by removing the applied Network Policies
Microsoft.Network/virtualNetworks/subnets/writeCreates a virtual network subnet or updates an existing virtual network subnet
Microsoft.Network/virtualNetworks/virtualNetworkPeerings/deleteDeletes a virtual network peering
Microsoft.Network/virtualNetworks/virtualNetworkPeerings/readGets a virtual network peering definition
Microsoft.Network/virtualNetworks/virtualNetworkPeerings/writeCreates a virtual network peering or updates an existing virtual network peering
Microsoft.Network/virtualNetworks/writeCreates a virtual network or updates an existing virtual network
Microsoft.Resources/deployments/deleteDeletes a deployment.
Microsoft.Resources/deployments/operations/readGets or lists deployment operations.
Microsoft.Resources/deployments/operationStatuses/readGets or lists deployment operation statuses.
Microsoft.Resources/deployments/readGets or lists deployments.
Microsoft.Resources/deployments/writeCreates or updates an deployment.
Microsoft.Resources/subscriptions/resourcegroups/readGets or lists resource groups.
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in
BuiltIn Policy
none
History
Date/Time (UTC ymd) (i) Change Change detail
2025-02-14 18:36:54 change: Actions Actions: 'add Microsoft.Network/virtualNetworks/join/action'
2024-10-04 17:51:49 add: Role d715fb95-a0f0-4f1c-8be6-5ad2d2767f67
JSON
api-version=2023-07-01-preview
Condition
    
    (
        !
        (
            ActionMatches {
            'Microsoft.Authorization/roleAssignments/delete'
            }
        )
    )
    OR@Resource[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals {
    d715fb95-a0f0-4f1c-8be6-5ad2d2767f67 (AVS Orchestrator Role),
    4d97b98b-1d4f-4787-a291-c67834d212e7 (Network Contributor),
    49fc33c1-886f-4b21-a00e-1d9993234734 (AVS on Fleet VIS Role)
    }