Name | Virtual Machine Data Access Administrator (preview) | ||||||||||||||||||||||||||||||
Id | 66f75aeb-eabe-4b70-9f1e-c350c4c9ad04 | ||||||||||||||||||||||||||||||
Description | Manage access to Virtual Machines by adding or removing role assignments for the Virtual Machine Administrator Login and Virtual Machine User Login roles. Includes an ABAC condition to constrain role assignments. | ||||||||||||||||||||||||||||||
CreatedOn | 2023-08-07 15:25:15 UTC | ||||||||||||||||||||||||||||||
UpdatedOn | 2023-10-31 15:13:38 UTC | ||||||||||||||||||||||||||||||
History |
|
||||||||||||||||||||||||||||||
Permissions summary | Effective control plane and data plane operations: 74 (unique operations) •action: 7 •delete: 2 •read: 62 •write: 3 Actions: 14 Resolved control plane operations from Actions: 74 Effective control plane operations: 74 •action: 7 •delete: 2 •read: 62 •write: 3 NotActions: 0 Resolved control plane operations from NotActions: 0 Effective denied control plane operations: 16098 DataActions: 0 Resolved data plane operations: 0 Effective data plane operations: 0 NotDataActions: 0 Resolved data plane operations from NotDataActions: 0 Effective denied data plane operations: 3303 |
||||||||||||||||||||||||||||||
Actions |
|
||||||||||||||||||||||||||||||
NotActions | n/a | ||||||||||||||||||||||||||||||
DataActions | n/a | ||||||||||||||||||||||||||||||
NotDataActions | n/a | ||||||||||||||||||||||||||||||
Used in BuiltIn Policy |
none | ||||||||||||||||||||||||||||||
JSON |
|
||||||||||||||||||||||||||||||
Condition |
( ( ! ( ActionMatches { 'Microsoft.Authorization/roleAssignments/write' } ) ) OR ( @Request[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals { 1c0163c0-47e6-4577-8991-ea5c82e286e4 (Virtual Machine Administrator Login), fb879df8-f326-4884-b1cf-06f3ad86be52 (Virtual Machine User Login) } ) ) AND ( ( ! ( ActionMatches { 'Microsoft.Authorization/roleAssignments/delete' } ) ) OR ( @Resource[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals { 1c0163c0-47e6-4577-8991-ea5c82e286e4 (Virtual Machine Administrator Login), fb879df8-f326-4884-b1cf-06f3ad86be52 (Virtual Machine User Login) } ) ) |