last sync: 2024-Nov-25 18:54:42 UTC

Defender CSPM Storage Scanner Operator

Azure BuiltIn RBAC Role definition

NameDefender CSPM Storage Scanner Operator
Id8480c0f0-4509-4229-9339-7c10018cb8c4
DescriptionLets you enable and configure Microsoft Defender CSPM's sensitive data discovery feature on your storage accounts. Includes an ABAC condition to limit role assignments.
CreatedOn2024-02-23 11:40:48 UTC
UpdatedOn2024-09-30 15:04:07 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2024-09-30 17:51:34 change: Actions Actions: 'add Microsoft.Security/datascanners/read; add Microsoft.Security/datascanners/write; add Microsoft.Security/dataScanners/delete'
2024-04-30 17:48:19 add: Role 8480c0f0-4509-4229-9339-7c10018cb8c4
Permissions summary Effective control plane and data plane operations: 56 (unique operations)
•action: 7
•delete: 3
•read: 41
•write: 5

Actions: 13
Resolved control plane operations from Actions: 56
Effective control plane operations: 56
•action: 7
•delete: 3
•read: 41
•write: 5

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 16116

DataActions: 0
Resolved data plane operations: 0
Effective data plane operations: 0

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3303
Actions
Operation Description
Microsoft.Authorization/*/readwildcarded / no description
Microsoft.Authorization/roleAssignments/deleteDelete a role assignment at the specified scope.
Microsoft.Authorization/roleAssignments/writeCreate a role assignment at the specified scope.
Microsoft.Management/managementGroups/readList management groups for the authenticated user.
Microsoft.Resources/deployments/*wildcarded / no description
Microsoft.Resources/subscriptions/readRuft die Liste der Abonnements ab.
Microsoft.Resources/subscriptions/resourceGroups/readRuft Ressourcengruppen ab oder listet diese auf.
Microsoft.Security/dataScanners/deleteDeletes the datascanners for the scope
Microsoft.Security/datascanners/readGets the datascanners for the scope
Microsoft.Security/datascanners/writeCreates or updates the datascanners for the scope
Microsoft.Storage/storageAccounts/readReturns the list of storage accounts or gets the properties for the specified storage account.
Microsoft.Storage/storageAccounts/writeCreates a storage account with the specified parameters or update the properties or tags or adds custom domain for the specified storage account.
Microsoft.Support/*wildcarded / no description
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in
BuiltIn Policy
none
JSON
api-version=2023-07-01-preview
Condition
     @Request[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals {
    2a2b9908-6ea1-4ae2-8e65-a410df84e7d1 (Storage Blob Data Reader),
    b8eda974-7b85-4f76-af95-65846b26df6d (Storage File Data Privileged Reader)
    }
     @Resource[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals {
    2a2b9908-6ea1-4ae2-8e65-a410df84e7d1 (Storage Blob Data Reader),
    b8eda974-7b85-4f76-af95-65846b26df6d (Storage File Data Privileged Reader)
    }