last sync: 2024-Aug-15 18:18:54 UTC

PostgreSQL Flexible Management Service Contributor

Azure BuiltIn RBAC Role definition

NamePostgreSQL Flexible Management Service Contributor
Ida60b64c0-1adf-4051-956a-78f3ae578c7d
DescriptionCreate, read, modify, and delete required resources objects to be used by Azure PostgreSQL Flexible servers.
CreatedOn2024-08-06 15:15:42 UTC
UpdatedOn2024-08-06 15:15:42 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2024-08-06 18:20:07 add: Role a60b64c0-1adf-4051-956a-78f3ae578c7d
Permissions summary Effective control plane and data plane operations: 168 (unique operations)
•: 1
•action: 28
•delete: 24
•read: 88
•write: 27

Actions: 131
Resolved control plane operations from Actions: 168
Effective control plane operations: 168
•: 1
•action: 28
•delete: 24
•read: 88
•write: 27

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 15433

DataActions: 0
Resolved data plane operations: 0
Effective data plane operations: 0

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3240
Actions
Operation Description
Microsoft.Authorization/*/readwildcarded / no description
Microsoft.Compute/diskEncryptionSets/*wildcarded / no description
Microsoft.Compute/diskEncryptionSets/deleteDelete a disk encryption set
Microsoft.Compute/diskEncryptionSets/readGet the properties of a disk encryption set
Microsoft.Compute/diskEncryptionSets/writeCreate a new disk encryption set or update an existing one
Microsoft.Compute/disks/beginGetAccess/actionGet the SAS URI of the Disk for blob access
Microsoft.Compute/disks/deleteDeletes the Disk
Microsoft.Compute/disks/endGetAccess/actionRevoke the SAS URI of the Disk
Microsoft.Compute/disks/readGet the properties of a Disk
Microsoft.Compute/disks/writeCreates a new Disk or updates an existing one
Microsoft.Compute/galleries/images/versions/readGets the properties of Gallery Image Version
Microsoft.Compute/locations/DiskOperations/readGets the status of an asynchronous Disk operation
Microsoft.Compute/locations/operations/readGets the status of an asynchronous operation
Microsoft.Compute/locations/usages/readGets service limits and current usage quantities for the subscription's compute resources in a location
Microsoft.Compute/skus/readGets the list of Microsoft.Compute SKUs available for your Subscription
Microsoft.Compute/snapshots/beginGetAccess/actionGet the SAS URI of the Snapshot for blob access
Microsoft.Compute/snapshots/deleteDelete a Snapshot
Microsoft.Compute/snapshots/endGetAccess/actionRevoke the SAS URI of the Snapshot
Microsoft.Compute/snapshots/readGet the properties of a Snapshot
Microsoft.Compute/snapshots/writeCreate a new Snapshot or update an existing one
Microsoft.Compute/virtualMachines/deallocate/actionPowers off the virtual machine and releases the compute resources
Microsoft.Compute/virtualMachines/deleteDeletes the virtual machine
Microsoft.Compute/virtualMachines/extensions/deleteDeletes the virtual machine extension
Microsoft.Compute/virtualMachines/extensions/readGet the properties of a virtual machine extension
Microsoft.Compute/virtualMachines/extensions/writeCreates a new virtual machine extension or updates an existing one
Microsoft.Compute/virtualMachines/powerOff/actionPowers off the virtual machine. Note that the virtual machine will continue to be billed.
Microsoft.Compute/virtualMachines/readGet the properties of a virtual machine
Microsoft.Compute/virtualMachines/restart/actionRestarts the virtual machine
Microsoft.Compute/virtualMachines/runCommand/actionExecutes a predefined script on the virtual machine
Microsoft.Compute/virtualMachines/start/actionStarts the virtual machine
Microsoft.Compute/virtualMachines/writeCreates a new virtual machine or updates an existing virtual machine
Microsoft.DocumentDB/databaseAccounts/readReads a database account.
Microsoft.Insights/alertRules/*wildcarded / no description
Microsoft.Insights/diagnosticSettings/readRead a resource diagnostic setting
microsoft.insights/diagnosticSettings/writeCreate or update a resource diagnostic setting
microsoft.insights/metrics/readRead metrics
Microsoft.KeyVault/vaults/deleteDeletes a key vault
Microsoft.KeyVault/vaults/deploy/actionEnables access to secrets in a key vault when deploying Azure resources
Microsoft.KeyVault/vaults/readView the properties of a key vault
Microsoft.KeyVault/vaults/writeCreates a new key vault or updates the properties of an existing key vault. Certain properties may require more permissions.
Microsoft.ManagedIdentity/userAssignedIdentities/assign/actionRBAC action for assigning an existing user assigned identity to a resource
Microsoft.ManagedIdentity/userAssignedIdentities/deleteDeletes an existing user assigned identity
Microsoft.ManagedIdentity/userAssignedIdentities/federatedIdentityCredentials/readGet or list Federated Identity Credentials
Microsoft.ManagedIdentity/userAssignedIdentities/readGets an existing user assigned identity
Microsoft.ManagedIdentity/userAssignedIdentities/writeCreates a new user assigned identity or updates the tags associated with an existing user assigned identity
Microsoft.Network/loadBalancers/backendAddressPools/backendPoolAddresses/readLists the backend addresses of the Load Balancer backend address pool
Microsoft.Network/loadBalancers/backendAddressPools/deleteDeletes a load balancer backend address pool
Microsoft.Network/loadBalancers/backendAddressPools/health/actionGet Health Details of Backend Instance
Microsoft.Network/loadBalancers/backendAddressPools/join/actionJoins a load balancer backend address pool. Not Alertable.
Microsoft.Network/loadBalancers/backendAddressPools/readGets a load balancer backend address pool definition
Microsoft.Network/loadBalancers/backendAddressPools/writeCreates a load balancer backend address pool or updates an existing load balancer backend address pool
Microsoft.Network/loadBalancers/deleteDeletes a load balancer
Microsoft.Network/loadBalancers/inboundNatRules/deleteDeletes a load balancer inbound nat rule
Microsoft.Network/loadBalancers/inboundNatRules/join/actionJoins a load balancer inbound nat rule. Not Alertable.
Microsoft.Network/loadBalancers/inboundNatRules/readGets a load balancer inbound nat rule definition
Microsoft.Network/loadBalancers/inboundNatRules/writeCreates a load balancer inbound nat rule or updates an existing load balancer inbound nat rule
Microsoft.Network/loadBalancers/loadBalancingRules/readGets a load balancer load balancing rule definition
Microsoft.Network/loadBalancers/outboundRules/readGets a load balancer outbound rule definition
Microsoft.Network/loadBalancers/probes/readGets a load balancer probe
Microsoft.Network/loadBalancers/readGets a load balancer definition
Microsoft.Network/loadBalancers/writeCreates a load balancer or updates an existing load balancer
Microsoft.Network/locations/operationResults/readGets operation result of an async POST or DELETE operation
Microsoft.Network/locations/operations/readGets operation resource that represents status of an asynchronous operation
Microsoft.Network/locations/serviceTags/readGet Service Tags
Microsoft.Network/locations/supportedVirtualMachineSizes/readGets supported virtual machines sizes
Microsoft.Network/locations/usages/readGets the resources usage metrics
Microsoft.Network/networkInterfaces/deleteDeletes a network interface
Microsoft.Network/networkInterfaces/join/actionJoins a Virtual Machine to a network interface. Not Alertable.
Microsoft.Network/networkInterfaces/readGets a network interface definition.
Microsoft.Network/networkInterfaces/writeCreates a network interface or updates an existing network interface.
Microsoft.Network/networkSecurityGroups/deleteDeletes a network security group
Microsoft.Network/networkSecurityGroups/join/actionJoins a network security group. Not Alertable.
Microsoft.Network/networkSecurityGroups/readGets a network security group definition
Microsoft.Network/networkSecurityGroups/securityRules/readGets a security rule definition
Microsoft.Network/networkSecurityGroups/writeCreates a network security group or updates an existing network security group
Microsoft.Network/networkWatchers/readGet the network watcher definition
Microsoft.Network/privateDnsOperationStatuses/readGets status of a Private DNS operation
Microsoft.Network/privateDnsZones/deleteDelete a Private DNS zone.
Microsoft.Network/privateDnsZones/readGet the Private DNS zone properties, in JSON format. Note that this command does not retrieve the virtual networks to which the Private DNS zone is linked or the record sets contained within the zone.
Microsoft.Network/privateDnsZones/writeCreate or update a Private DNS zone within a resource group. Note that this command cannot be used to create or update virtual network links or record sets within the zone.
Microsoft.Network/publicIPAddresses/deleteDeletes a public Ip address.
Microsoft.Network/publicIPAddresses/join/actionJoins a public ip address. Not Alertable.
Microsoft.Network/publicIPAddresses/readGets a public ip address definition.
Microsoft.Network/publicIPAddresses/writeCreates a public Ip address or updates an existing public Ip address.
Microsoft.Network/virtualNetworks/deleteDeletes a virtual network
Microsoft.Network/virtualNetworks/readGet the virtual network definition
Microsoft.Network/virtualNetworks/remoteVirtualNetworkPeeringProxies/deleteno description given
Microsoft.Network/virtualNetworks/remoteVirtualNetworkPeeringProxies/writeno description given
Microsoft.Network/virtualNetworks/subnets/deleteDeletes a virtual network subnet
Microsoft.Network/virtualNetworks/subnets/join/actionJoins a virtual network. Not Alertable.
Microsoft.Network/virtualNetworks/subnets/readGets a virtual network subnet definition
Microsoft.Network/virtualNetworks/subnets/serviceAssociationLinks/deleteno description given
Microsoft.Network/virtualNetworks/subnets/serviceAssociationLinks/Details/readno description given
Microsoft.Network/virtualNetworks/subnets/serviceAssociationLinks/readno description given
Microsoft.Network/virtualNetworks/subnets/serviceAssociationLinks/validate/actionno description given
Microsoft.Network/virtualNetworks/subnets/serviceAssociationLinks/writeno description given
Microsoft.Network/virtualNetworks/subnets/writeCreates a virtual network subnet or updates an existing virtual network subnet
Microsoft.Network/virtualNetworks/virtualNetworkPeerings/deleteDeletes a virtual network peering
Microsoft.Network/virtualNetworks/virtualNetworkPeerings/readGets a virtual network peering definition
Microsoft.Network/virtualNetworks/virtualNetworkPeerings/writeCreates a virtual network peering or updates an existing virtual network peering
Microsoft.Network/virtualNetworks/writeCreates a virtual network or updates an existing virtual network
Microsoft.Resources/deployments/*wildcarded / no description
Microsoft.Resources/deployments/operations/readGets or lists deployment operations.
Microsoft.Resources/deployments/readGets or lists deployments.
Microsoft.Resources/subscriptions/providers/readGets or lists resource providers.
Microsoft.Resources/subscriptions/resourcegroups/readGets or lists resource groups.
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups.
Microsoft.Resources/subscriptions/resourcegroups/writeCreates or updates a resource group.
Microsoft.Security/assessments/readGet security assessments on your subscription
Microsoft.Storage/locations/usages/readReturns the limit and the current usage count for resources in the specified subscription
Microsoft.Storage/operations/readPolls the status of an asynchronous operation.
Microsoft.Storage/skus/readLists the Skus supported by Microsoft.Storage.
Microsoft.Storage/storageAccounts/blobServices/containers/deleteReturns the result of deleting a container
Microsoft.Storage/storageAccounts/blobServices/containers/readReturns list of containers
Microsoft.Storage/storageAccounts/blobServices/containers/writeReturns the result of put blob container
Microsoft.Storage/storageAccounts/blobServices/readReturns blob service properties or statistics
Microsoft.Storage/storageAccounts/deleteDeletes an existing storage account.
Microsoft.Storage/storageAccounts/fileservices/readGet file service properties
Microsoft.Storage/storageAccounts/fileServices/shares/readList file shares
Microsoft.Storage/storageAccounts/listKeys/actionReturns the access keys for the specified storage account.
Microsoft.Storage/storageAccounts/managementPolicies/deleteDelete storage account management policies
Microsoft.Storage/storageAccounts/managementPolicies/readGet storage management account policies
Microsoft.Storage/storageAccounts/managementPolicies/writePut storage account management policies
Microsoft.Storage/storageAccounts/privateEndpointConnections/readGet Private Endpoint Connection
Microsoft.Storage/storageAccounts/queueServices/queues/readReturns a queue or a list of queues.
Microsoft.Storage/storageAccounts/readReturns the list of storage accounts or gets the properties for the specified storage account.
Microsoft.Storage/storageAccounts/regenerateKey/actionRegenerates the access keys for the specified storage account.
Microsoft.Storage/storageAccounts/sharedIdentities/readno description given
Microsoft.Storage/storageAccounts/sharedIdentities/writeno description given
Microsoft.Storage/storageAccounts/tableServices/tables/readQuery tables
Microsoft.Storage/storageAccounts/writeCreates a storage account with the specified parameters or update the properties or tags or adds custom domain for the specified storage account.
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in
BuiltIn Policy
none
JSON
api-version=2023-07-01-preview
Condition

    (
        (
            !
            (
                ActionMatches {
                'Microsoft.Authorization/roleAssignments/write'
                }
            )
        )
        OR
        (
            @Request[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals  {
            ba92f5b4-2d11-453d-a403-e96b0029c9fe (Storage Blob Data Contributor),
            c12c1c16-33a1-487b-954d-41c89c60f349 (Reader and Data Access)
            }
        )
    )
    AND
    (
        (
            !
            (
                ActionMatches {
                'Microsoft.Authorization/roleAssignments/delete'
                }
            )
        )
        OR
        (
            @Resource[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals  {
            ba92f5b4-2d11-453d-a403-e96b0029c9fe (Storage Blob Data Contributor),
            c12c1c16-33a1-487b-954d-41c89c60f349 (Reader and Data Access)
            }
        )
    )