Skip to content

Commit f8fa0bb

Browse files
Merge pull request #314547 from rolyon/rolyon-roles-april-2026
[Azure RBAC] Roles and permissions for April 2026
2 parents c212414 + c20f448 commit f8fa0bb

39 files changed

Lines changed: 520 additions & 217 deletions

articles/role-based-access-control/built-in-roles.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.workload: identity
77
author: rolyon
88
manager: pmwongera
99
ms.author: rolyon
10-
ms.date: 02/23/2026
10+
ms.date: 04/09/2026
1111
ms.custom: generated
1212
---
1313

articles/role-based-access-control/built-in-roles/ai-machine-learning.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.workload: identity
77
author: rolyon
88
manager: pmwongera
99
ms.author: rolyon
10-
ms.date: 02/23/2026
10+
ms.date: 04/09/2026
1111
ms.custom: generated
1212
---
1313

articles/role-based-access-control/built-in-roles/analytics.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.workload: identity
77
author: rolyon
88
manager: pmwongera
99
ms.author: rolyon
10-
ms.date: 02/23/2026
10+
ms.date: 04/09/2026
1111
ms.custom: generated
1212
---
1313

articles/role-based-access-control/built-in-roles/compute.md

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1938,7 +1938,7 @@ View Virtual Machines in the portal and login as administrator
19381938
> | [Microsoft.Network](../permissions/networking.md#microsoftnetwork)/networkInterfaces/read | Gets a network interface definition. |
19391939
> | [Microsoft.Compute](../permissions/compute.md#microsoftcompute)/virtualMachines/*/read | |
19401940
> | [Microsoft.HybridCompute](../permissions/hybrid-multicloud.md#microsofthybridcompute)/machines/*/read | |
1941-
> | [Microsoft.HybridConnectivity](../permissions/hybrid-multicloud.md#microsofthybridconnectivity)/endpoints/listCredentials/action | List the endpoint access credentials to the resource. |
1941+
> | [Microsoft.HybridConnectivity](../permissions/hybrid-multicloud.md#microsofthybridconnectivity)/endpoints/listCredentials/action | Gets the endpoint access credentials to the resource. |
19421942
> | **NotActions** | |
19431943
> | *none* | |
19441944
> | **DataActions** | |
@@ -2192,7 +2192,7 @@ View Virtual Machines in the portal and login as a local user configured on the
21922192
> | Actions | Description |
21932193
> | --- | --- |
21942194
> | [Microsoft.HybridCompute](../permissions/hybrid-multicloud.md#microsofthybridcompute)/machines/*/read | |
2195-
> | [Microsoft.HybridConnectivity](../permissions/hybrid-multicloud.md#microsofthybridconnectivity)/endpoints/listCredentials/action | List the endpoint access credentials to the resource. |
2195+
> | [Microsoft.HybridConnectivity](../permissions/hybrid-multicloud.md#microsofthybridconnectivity)/endpoints/listCredentials/action | Gets the endpoint access credentials to the resource. |
21962196
> | **NotActions** | |
21972197
> | *none* | |
21982198
> | **DataActions** | |
@@ -2240,7 +2240,7 @@ View Virtual Machines in the portal and login as a regular user.
22402240
> | [Microsoft.Network](../permissions/networking.md#microsoftnetwork)/networkInterfaces/read | Gets a network interface definition. |
22412241
> | [Microsoft.Compute](../permissions/compute.md#microsoftcompute)/virtualMachines/*/read | |
22422242
> | [Microsoft.HybridCompute](../permissions/hybrid-multicloud.md#microsofthybridcompute)/machines/*/read | |
2243-
> | [Microsoft.HybridConnectivity](../permissions/hybrid-multicloud.md#microsofthybridconnectivity)/endpoints/listCredentials/action | List the endpoint access credentials to the resource. |
2243+
> | [Microsoft.HybridConnectivity](../permissions/hybrid-multicloud.md#microsofthybridconnectivity)/endpoints/listCredentials/action | Gets the endpoint access credentials to the resource. |
22442244
> | **NotActions** | |
22452245
> | *none* | |
22462246
> | **DataActions** | |
@@ -2549,11 +2549,11 @@ Let's you manage the OS of your resource via Windows Admin Center as an administ
25492549
> | [Microsoft.Network](../permissions/networking.md#microsoftnetwork)/networkWatchers/securityGroupView/action | View the configured and effective network security group rules applied on a VM. |
25502550
> | [Microsoft.Network](../permissions/networking.md#microsoftnetwork)/networkSecurityGroups/securityRules/read | Gets a security rule definition |
25512551
> | [Microsoft.Network](../permissions/networking.md#microsoftnetwork)/networkSecurityGroups/securityRules/write | Creates a security rule or updates an existing security rule |
2552-
> | [Microsoft.HybridConnectivity](../permissions/hybrid-multicloud.md#microsofthybridconnectivity)/endpoints/write | Create or update the endpoint to the target resource. |
2553-
> | [Microsoft.HybridConnectivity](../permissions/hybrid-multicloud.md#microsofthybridconnectivity)/endpoints/read | Get or list of endpoints to the target resource. |
2554-
> | [Microsoft.HybridConnectivity](../permissions/hybrid-multicloud.md#microsofthybridconnectivity)/endpoints/serviceConfigurations/write | Create or update the serviceConfigurations to the endpoints resource. |
2555-
> | [Microsoft.HybridConnectivity](../permissions/hybrid-multicloud.md#microsofthybridconnectivity)/endpoints/serviceConfigurations/read | Get or list of serviceConfigurations to the endpoints resource. |
2556-
> | [Microsoft.HybridConnectivity](../permissions/hybrid-multicloud.md#microsofthybridconnectivity)/endpoints/listManagedProxyDetails/action | List the managed proxy details to the resource. |
2552+
> | [Microsoft.HybridConnectivity](../permissions/hybrid-multicloud.md#microsofthybridconnectivity)/endpoints/write | Update the endpoint to the target resource. |
2553+
> | [Microsoft.HybridConnectivity](../permissions/hybrid-multicloud.md#microsofthybridconnectivity)/endpoints/read | Gets the endpoint to the resource. |
2554+
> | [Microsoft.HybridConnectivity](../permissions/hybrid-multicloud.md#microsofthybridconnectivity)/endpoints/serviceConfigurations/write | Update the service details in the service configurations of the target resource. |
2555+
> | [Microsoft.HybridConnectivity](../permissions/hybrid-multicloud.md#microsofthybridconnectivity)/endpoints/serviceConfigurations/read | Gets the details about the service to the resource. |
2556+
> | [Microsoft.HybridConnectivity](../permissions/hybrid-multicloud.md#microsofthybridconnectivity)/endpoints/listManagedProxyDetails/action | Fetches the managed proxy details |
25572557
> | [Microsoft.Compute](../permissions/compute.md#microsoftcompute)/virtualMachines/read | Get the properties of a virtual machine |
25582558
> | [Microsoft.Compute](../permissions/compute.md#microsoftcompute)/virtualMachines/patchAssessmentResults/latest/read | Retrieves the summary of the latest patch assessment operation |
25592559
> | [Microsoft.Compute](../permissions/compute.md#microsoftcompute)/virtualMachines/patchAssessmentResults/latest/softwarePatches/read | Retrieves list of patches assessed during the last patch assessment operation |

articles/role-based-access-control/built-in-roles/containers.md

Lines changed: 11 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.workload: identity
77
author: rolyon
88
manager: pmwongera
99
ms.author: rolyon
10-
ms.date: 02/23/2026
10+
ms.date: 04/09/2026
1111
ms.custom: generated
1212
---
1313

@@ -1024,6 +1024,7 @@ Grants read/write access to Azure resources provided by Azure Kubernetes Fleet M
10241024
> | --- | --- |
10251025
> | [Microsoft.ContainerService](../permissions/containers.md#microsoftcontainerservice)/fleets/* | |
10261026
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/* | Create and manage a deployment |
1027+
> | [Microsoft.ContainerService](../permissions/containers.md#microsoftcontainerservice)/fleetMemberships/* | |
10271028
> | **NotActions** | |
10281029
> | *none* | |
10291030
> | **DataActions** | |
@@ -1043,7 +1044,8 @@ Grants read/write access to Azure resources provided by Azure Kubernetes Fleet M
10431044
{
10441045
"actions": [
10451046
"Microsoft.ContainerService/fleets/*",
1046-
"Microsoft.Resources/deployments/*"
1047+
"Microsoft.Resources/deployments/*",
1048+
"Microsoft.ContainerService/fleetMemberships/*"
10471049
],
10481050
"notActions": [],
10491051
"dataActions": [],
@@ -3511,7 +3513,7 @@ Read access to Container Apps ConnectedEnvironments.
35113513
> | --- | --- |
35123514
> | [Microsoft.Authorization](../permissions/management-and-governance.md#microsoftauthorization)/*/read | Read roles and role assignments |
35133515
> | [Microsoft.Insights](../permissions/monitor.md#microsoftinsights)/alertRules/* | Create and manage a classic metric alert |
3514-
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/* | Create and manage a deployment |
3516+
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/read | Gets or lists deployments. |
35153517
> | [Microsoft.App](../permissions/compute.md#microsoftapp)/connectedEnvironments/read | Get a Connected Environment |
35163518
> | [Microsoft.App](../permissions/compute.md#microsoftapp)/connectedEnvironments/*/read | |
35173519
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/subscriptions/resourceGroups/read | Gets or lists resource groups. |
@@ -3535,7 +3537,7 @@ Read access to Container Apps ConnectedEnvironments.
35353537
"actions": [
35363538
"Microsoft.Authorization/*/read",
35373539
"Microsoft.Insights/alertRules/*",
3538-
"Microsoft.Resources/deployments/*",
3540+
"Microsoft.Resources/deployments/read",
35393541
"Microsoft.App/connectedEnvironments/read",
35403542
"Microsoft.App/connectedEnvironments/*/read",
35413543
"Microsoft.Resources/subscriptions/resourceGroups/read"
@@ -4869,6 +4871,8 @@ Grants Microsoft Defender for Cloud access to Azure Kubernetes Services
48694871
> | [Microsoft.Features](../permissions/management-and-governance.md#microsoftfeatures)/providers/features/register/action | Registers the feature for a subscription in a given resource provider. |
48704872
> | [Microsoft.Security](../permissions/security.md#microsoftsecurity)/pricings/securityoperators/read | Gets the security operators for the scope |
48714873
> | [Microsoft.Security](../permissions/security.md#microsoftsecurity)/securityOperators/read | Gets the securityoperators for the scope |
4874+
> | [Microsoft.Authorization](../permissions/management-and-governance.md#microsoftauthorization)/policyAssignments/read | Get information about a policy assignment. |
4875+
> | [Microsoft.Authorization](../permissions/management-and-governance.md#microsoftauthorization)/policySetDefinitions/read | Get information about a policy set definition. |
48724876
> | **NotActions** | |
48734877
> | *none* | |
48744878
> | **DataActions** | |
@@ -4895,7 +4899,9 @@ Grants Microsoft Defender for Cloud access to Azure Kubernetes Services
48954899
"Microsoft.Features/providers/features/read",
48964900
"Microsoft.Features/providers/features/register/action",
48974901
"Microsoft.Security/pricings/securityoperators/read",
4898-
"Microsoft.Security/securityOperators/read"
4902+
"Microsoft.Security/securityOperators/read",
4903+
"Microsoft.Authorization/policyAssignments/read",
4904+
"Microsoft.Authorization/policySetDefinitions/read"
48994905
],
49004906
"notActions": [],
49014907
"dataActions": [],

articles/role-based-access-control/built-in-roles/databases.md

Lines changed: 15 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.workload: identity
77
author: rolyon
88
manager: pmwongera
99
ms.author: rolyon
10-
ms.date: 02/23/2026
10+
ms.date: 04/09/2026
1111
ms.custom: generated
1212
---
1313

@@ -345,8 +345,15 @@ Role to allow backup vault to access PostgreSQL Flexible Server Resource APIs fo
345345
> [!div class="mx-tableFixed"]
346346
> | Actions | Description |
347347
> | --- | --- |
348+
> | [Microsoft.DBforPostgreSQL](../permissions/databases.md#microsoftdbforpostgresql)/flexibleServers/ltrBackup/action | Start LTR backup operation for a server |
349+
> | [Microsoft.DBforPostgreSQL](../permissions/databases.md#microsoftdbforpostgresql)/flexibleServers/ltrBackupAccess/action | Start LTR backup access operation for a server |
348350
> | [Microsoft.DBforPostgreSQL](../permissions/databases.md#microsoftdbforpostgresql)/flexibleServers/ltrBackupOperations/read | Returns the list of PostgreSQL server long term backup operation tracking. |
351+
> | [Microsoft.DBforPostgreSQL](../permissions/databases.md#microsoftdbforpostgresql)/flexibleServers/ltrBackupPreCheck/action | Start LTR backup pre-check operation for a server |
349352
> | [Microsoft.DBforPostgreSQL](../permissions/databases.md#microsoftdbforpostgresql)/flexibleServers/ltrPreBackup/action | Checks if a server is ready for a long term backup |
353+
> | [Microsoft.DBforPostgreSQL](../permissions/databases.md#microsoftdbforpostgresql)/flexibleServers/ltrRestoreFinalize/action | Start LTR restore finalize operation for a server |
354+
> | [Microsoft.DBforPostgreSQL](../permissions/databases.md#microsoftdbforpostgresql)/flexibleServers/ltrRestoreInitialize/action | Start LTR restore initialize operation for a server |
355+
> | [Microsoft.DBforPostgreSQL](../permissions/databases.md#microsoftdbforpostgresql)/flexibleServers/ltrRestorePreCheck/action | Start LTR restore pre-check operation for a server |
356+
> | [Microsoft.DBforPostgreSQL](../permissions/databases.md#microsoftdbforpostgresql)/flexibleServers/read | Return the list of servers or gets the properties for the specified server. |
350357
> | [Microsoft.DBforPostgreSQL](../permissions/databases.md#microsoftdbforpostgresql)/flexibleServers/startLtrBackup/action | Start long term backup for a server |
351358
> | [Microsoft.DBforPostgreSQL](../permissions/databases.md#microsoftdbforpostgresql)/locations/azureAsyncOperation/read | Return PostgreSQL Server Operation Results |
352359
> | [Microsoft.DBforPostgreSQL](../permissions/databases.md#microsoftdbforpostgresql)/locations/operationResults/read | Return PostgreSQL Server Operation Results |
@@ -370,8 +377,15 @@ Role to allow backup vault to access PostgreSQL Flexible Server Resource APIs fo
370377
"permissions": [
371378
{
372379
"actions": [
380+
"Microsoft.DBforPostgreSQL/flexibleServers/ltrBackup/action",
381+
"Microsoft.DBforPostgreSQL/flexibleServers/ltrBackupAccess/action",
373382
"Microsoft.DBforPostgreSQL/flexibleServers/ltrBackupOperations/read",
383+
"Microsoft.DBforPostgreSQL/flexibleServers/ltrBackupPreCheck/action",
374384
"Microsoft.DBforPostgreSQL/flexibleServers/ltrPreBackup/action",
385+
"Microsoft.DBforPostgreSQL/flexibleServers/ltrRestoreFinalize/action",
386+
"Microsoft.DBforPostgreSQL/flexibleServers/ltrRestoreInitialize/action",
387+
"Microsoft.DBforPostgreSQL/flexibleServers/ltrRestorePreCheck/action",
388+
"Microsoft.DBforPostgreSQL/flexibleServers/read",
375389
"Microsoft.DBforPostgreSQL/flexibleServers/startLtrBackup/action",
376390
"Microsoft.DBforPostgreSQL/locations/azureAsyncOperation/read",
377391
"Microsoft.DBforPostgreSQL/locations/operationResults/read",

articles/role-based-access-control/built-in-roles/devops.md

Lines changed: 1 addition & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.workload: identity
77
author: rolyon
88
manager: pmwongera
99
ms.author: rolyon
10-
ms.date: 02/23/2026
10+
ms.date: 04/09/2026
1111
ms.custom: generated
1212
---
1313

@@ -1304,7 +1304,6 @@ View and list all load tests and load test resources but can not make any change
13041304
> | --- | --- |
13051305
> | [Microsoft.LoadTestService](../permissions/devops.md#microsoftloadtestservice)/*/read | Read load testing resources |
13061306
> | [Microsoft.Authorization](../permissions/management-and-governance.md#microsoftauthorization)/*/read | Read roles and role assignments |
1307-
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/* | Create and manage a deployment |
13081307
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/subscriptions/resourceGroups/read | Gets or lists resource groups. |
13091308
> | [Microsoft.Insights](../permissions/monitor.md#microsoftinsights)/alertRules/* | Create and manage a classic metric alert |
13101309
> | **NotActions** | |
@@ -1330,7 +1329,6 @@ View and list all load tests and load test resources but can not make any change
13301329
"actions": [
13311330
"Microsoft.LoadTestService/*/read",
13321331
"Microsoft.Authorization/*/read",
1333-
"Microsoft.Resources/deployments/*",
13341332
"Microsoft.Resources/subscriptions/resourceGroups/read",
13351333
"Microsoft.Insights/alertRules/*"
13361334
],
@@ -1466,7 +1464,6 @@ View and list all Playwright Workspace resources and tests but can not make any
14661464
> | [Microsoft.Loadtestservice](../permissions/devops.md#microsoftloadtestservice)/playwrightworkspaces/*/read | |
14671465
> | [Microsoft.Loadtestservice](../permissions/devops.md#microsoftloadtestservice)/locations/playwrightquotas/*/read | |
14681466
> | [Microsoft.Authorization](../permissions/management-and-governance.md#microsoftauthorization)/*/read | Read roles and role assignments |
1469-
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/deployments/* | Create and manage a deployment |
14701467
> | [Microsoft.Resources](../permissions/management-and-governance.md#microsoftresources)/subscriptions/resourceGroups/read | Gets or lists resource groups. |
14711468
> | **NotActions** | |
14721469
> | *none* | |
@@ -1489,7 +1486,6 @@ View and list all Playwright Workspace resources and tests but can not make any
14891486
"Microsoft.Loadtestservice/playwrightworkspaces/*/read",
14901487
"Microsoft.Loadtestservice/locations/playwrightquotas/*/read",
14911488
"Microsoft.Authorization/*/read",
1492-
"Microsoft.Resources/deployments/*",
14931489
"Microsoft.Resources/subscriptions/resourceGroups/read"
14941490
],
14951491
"notActions": [],

articles/role-based-access-control/built-in-roles/general.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.workload: identity
77
author: rolyon
88
manager: pmwongera
99
ms.author: rolyon
10-
ms.date: 02/23/2026
10+
ms.date: 04/09/2026
1111
ms.custom: generated
1212
---
1313

articles/role-based-access-control/built-in-roles/hybrid-multicloud.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.workload: identity
77
author: rolyon
88
manager: pmwongera
99
ms.author: rolyon
10-
ms.date: 02/23/2026
10+
ms.date: 04/09/2026
1111
ms.custom: generated
1212
---
1313

articles/role-based-access-control/built-in-roles/identity.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.workload: identity
77
author: rolyon
88
manager: pmwongera
99
ms.author: rolyon
10-
ms.date: 02/23/2026
10+
ms.date: 04/09/2026
1111
ms.custom: generated
1212
---
1313

0 commit comments

Comments
 (0)