last sync: 2024-Nov-25 18:54:42 UTC

Kubernetes Agent Subscription Level Operator

Azure BuiltIn RBAC Role definition

NameKubernetes Agent Subscription Level Operator
Idada52afe-776a-4b4d-a8f2-55670d3d8178
DescriptionGrants Microsoft Defender for Cloud subscription level permissions needed to activate Containers plan
CreatedOn2024-11-14 10:01:45 UTC
UpdatedOn2024-11-14 10:01:45 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2024-11-14 18:51:40 add: Role ada52afe-776a-4b4d-a8f2-55670d3d8178
Permissions summary Effective control plane and data plane operations: 5 (unique operations)
•action: 2
•read: 2
•write: 1

Actions: 5
Resolved control plane operations from Actions: 5
Effective control plane operations: 5
•action: 2
•read: 2
•write: 1

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 16167

DataActions: 0
Resolved data plane operations: 0
Effective data plane operations: 0

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3303
Actions
Operation Description
Microsoft.OperationalInsights/workspaces/listKeys/actionRetrieves the list keys for the workspace. These keys are used to connect Microsoft Operational Insights agents to the workspace.
Microsoft.OperationalInsights/workspaces/readGets an existing workspace
Microsoft.OperationalInsights/workspaces/sharedkeys/actionRetrieves the shared keys for the workspace. These keys are used to connect Microsoft Operational Insights agents to the workspace.
Microsoft.OperationalInsights/workspaces/sharedkeys/readRetrieves the shared keys for the workspace. These keys are used to connect Microsoft Operational Insights agents to the workspace.
Microsoft.OperationalInsights/workspaces/writeCreates a new workspace or links to an existing workspace by providing the customer id from the existing workspace.
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in
BuiltIn Policy
none
JSON
api-version=2023-07-01-preview
Condition none