Back to Dashboard

SQL Security Manager

Azure Built-in Role

Role Information

Details and metadata

Role ID
056cd41c-7e88-42e1-933e-88ba6a50c9c3
Type
BuiltInRole
Last Updated (Azure)
2025-10-03 19:16:17

Change History

Track all modifications to this role

2025-10-03 19:16:17 Initial Scan
View details
{
  "properties": {
    "roleName": "SQL Security Manager",
    "type": "BuiltInRole",
    "description": "Lets you manage the security-related policies of SQL servers and databases, but not access to them.",
    "assignableScopes": [
      "/"
    ],
    "permissions": [
      {
        "actions": [
          "Microsoft.Authorization/*/read",
          "Microsoft.Insights/alertRules/*",
          "Microsoft.Network/virtualNetworks/subnets/joinViaServiceEndpoint/action",
          "Microsoft.ResourceHealth/availabilityStatuses/read",
          "Microsoft.Resources/deployments/*",
          "Microsoft.Resources/subscriptions/resourceGroups/read",
          "Microsoft.Sql/locations/administratorAzureAsyncOperation/read",
          "Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/read",
          "Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/write",
          "Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/read",
          "Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/write",
          "Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/read",
          "Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/write",
          "Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/read",
          "Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/write",
          "Microsoft.Sql/managedInstances/databases/currentSensitivityLabels/*",
          "Microsoft.Sql/managedInstances/databases/recommendedSensitivityLabels/*",
          "Microsoft.Sql/managedInstances/databases/schemas/tables/columns/sensitivityLabels/*",
          "Microsoft.Sql/managedInstances/databases/securityAlertPolicies/*",
          "Microsoft.Sql/managedInstances/databases/sensitivityLabels/*",
          "Microsoft.Sql/managedInstances/databases/vulnerabilityAssessments/*",
          "Microsoft.Sql/servers/advancedThreatProtectionSettings/read",
          "Microsoft.Sql/servers/advancedThreatProtectionSettings/write",
          "Microsoft.Sql/managedInstances/securityAlertPolicies/*",
          "Microsoft.Sql/managedInstances/databases/transparentDataEncryption/*",
          "Microsoft.Sql/managedInstances/vulnerabilityAssessments/*",
          "Microsoft.Sql/managedInstances/serverConfigurationOptions/read",
          "Microsoft.Sql/managedInstances/serverConfigurationOptions/write",
          "Microsoft.Sql/locations/serverConfigurationOptionAzureAsyncOperation/read",
          "Microsoft.Sql/servers/advancedThreatProtectionSettings/read",
          "Microsoft.Sql/servers/advancedThreatProtectionSettings/write",
          "Microsoft.Sql/servers/auditingSettings/*",
          "Microsoft.Sql/servers/extendedAuditingSettings/*",
          "Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/read",
          "Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/write",
          "Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/read",
          "Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/write",
          "Microsoft.Sql/servers/databases/auditingSettings/*",
          "Microsoft.Sql/servers/databases/auditRecords/read",
          "Microsoft.Sql/servers/databases/currentSensitivityLabels/*",
          "Microsoft.Sql/servers/databases/dataMaskingPolicies/*",
          "Microsoft.Sql/servers/databases/extendedAuditingSettings/read",
          "Microsoft.Sql/servers/databases/read",
          "Microsoft.Sql/servers/databases/recommendedSensitivityLabels/*",
          "Microsoft.Sql/servers/databases/schemas/read",
          "Microsoft.Sql/servers/databases/schemas/tables/columns/read",
          "Microsoft.Sql/servers/databases/schemas/tables/columns/sensitivityLabels/*",
          "Microsoft.Sql/servers/databases/schemas/tables/read",
          "Microsoft.Sql/servers/databases/securityAlertPolicies/*",
          "Microsoft.Sql/servers/databases/securityMetrics/*",
          "Microsoft.Sql/servers/databases/sensitivityLabels/*",
          "Microsoft.Sql/servers/databases/transparentDataEncryption/*",
          "Microsoft.Sql/servers/databases/sqlvulnerabilityAssessments/*",
          "Microsoft.Sql/servers/databases/vulnerabilityAssessments/*",
          "Microsoft.Sql/servers/databases/vulnerabilityAssessmentScans/*",
          "Microsoft.Sql/servers/databases/vulnerabilityAssessmentSettings/*",
          "Microsoft.Sql/servers/devOpsAuditingSettings/*",
          "Microsoft.Sql/servers/firewallRules/*",
          "Microsoft.Sql/servers/read",
          "Microsoft.Sql/servers/securityAlertPolicies/*",
          "Microsoft.Sql/servers/sqlvulnerabilityAssessments/*",
          "Microsoft.Sql/servers/vulnerabilityAssessments/*",
          "Microsoft.Support/*",
          "Microsoft.Sql/servers/azureADOnlyAuthentications/*",
          "Microsoft.Sql/managedInstances/read",
          "Microsoft.Sql/managedInstances/azureADOnlyAuthentications/*",
          "Microsoft.Security/sqlVulnerabilityAssessments/*",
          "Microsoft.Sql/managedInstances/administrators/read",
          "Microsoft.Sql/servers/administrators/read",
          "Microsoft.Sql/servers/databases/ledgerDigestUploads/*",
          "Microsoft.Sql/locations/ledgerDigestUploadsAzureAsyncOperation/read",
          "Microsoft.Sql/locations/ledgerDigestUploadsOperationResults/read",
          "Microsoft.Sql/servers/externalPolicyBasedAuthorizations/*"
        ],
        "notActions": [],
        "dataActions": [],
        "notDataActions": []
      }
    ],
    "createdOn": "2015-06-16T18:44:40.46Z",
    "updatedOn": "2025-10-03T19:16:17.039Z",
    "createdBy": null,
    "updatedBy": null
  },
  "id": "/providers/Microsoft.Authorization/roleDefinitions/056cd41c-7e88-42e1-933e-88ba6a50c9c3",
  "type": "Microsoft.Authorization/roleDefinitions",
  "name": "056cd41c-7e88-42e1-933e-88ba6a50c9c3"
}

Latest Role JSON

Raw definition from Azure

{
  "properties": {
    "roleName": "SQL Security Manager",
    "type": "BuiltInRole",
    "description": "Lets you manage the security-related policies of SQL servers and databases, but not access to them.",
    "assignableScopes": [
      "/"
    ],
    "permissions": [
      {
        "actions": [
          "Microsoft.Authorization/*/read",
          "Microsoft.Insights/alertRules/*",
          "Microsoft.Network/virtualNetworks/subnets/joinViaServiceEndpoint/action",
          "Microsoft.ResourceHealth/availabilityStatuses/read",
          "Microsoft.Resources/deployments/*",
          "Microsoft.Resources/subscriptions/resourceGroups/read",
          "Microsoft.Sql/locations/administratorAzureAsyncOperation/read",
          "Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/read",
          "Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/write",
          "Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/read",
          "Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/write",
          "Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/read",
          "Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/write",
          "Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/read",
          "Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/write",
          "Microsoft.Sql/managedInstances/databases/currentSensitivityLabels/*",
          "Microsoft.Sql/managedInstances/databases/recommendedSensitivityLabels/*",
          "Microsoft.Sql/managedInstances/databases/schemas/tables/columns/sensitivityLabels/*",
          "Microsoft.Sql/managedInstances/databases/securityAlertPolicies/*",
          "Microsoft.Sql/managedInstances/databases/sensitivityLabels/*",
          "Microsoft.Sql/managedInstances/databases/vulnerabilityAssessments/*",
          "Microsoft.Sql/servers/advancedThreatProtectionSettings/read",
          "Microsoft.Sql/servers/advancedThreatProtectionSettings/write",
          "Microsoft.Sql/managedInstances/securityAlertPolicies/*",
          "Microsoft.Sql/managedInstances/databases/transparentDataEncryption/*",
          "Microsoft.Sql/managedInstances/vulnerabilityAssessments/*",
          "Microsoft.Sql/managedInstances/serverConfigurationOptions/read",
          "Microsoft.Sql/managedInstances/serverConfigurationOptions/write",
          "Microsoft.Sql/locations/serverConfigurationOptionAzureAsyncOperation/read",
          "Microsoft.Sql/servers/advancedThreatProtectionSettings/read",
          "Microsoft.Sql/servers/advancedThreatProtectionSettings/write",
          "Microsoft.Sql/servers/auditingSettings/*",
          "Microsoft.Sql/servers/extendedAuditingSettings/*",
          "Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/read",
          "Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/write",
          "Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/read",
          "Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/write",
          "Microsoft.Sql/servers/databases/auditingSettings/*",
          "Microsoft.Sql/servers/databases/auditRecords/read",
          "Microsoft.Sql/servers/databases/currentSensitivityLabels/*",
          "Microsoft.Sql/servers/databases/dataMaskingPolicies/*",
          "Microsoft.Sql/servers/databases/extendedAuditingSettings/read",
          "Microsoft.Sql/servers/databases/read",
          "Microsoft.Sql/servers/databases/recommendedSensitivityLabels/*",
          "Microsoft.Sql/servers/databases/schemas/read",
          "Microsoft.Sql/servers/databases/schemas/tables/columns/read",
          "Microsoft.Sql/servers/databases/schemas/tables/columns/sensitivityLabels/*",
          "Microsoft.Sql/servers/databases/schemas/tables/read",
          "Microsoft.Sql/servers/databases/securityAlertPolicies/*",
          "Microsoft.Sql/servers/databases/securityMetrics/*",
          "Microsoft.Sql/servers/databases/sensitivityLabels/*",
          "Microsoft.Sql/servers/databases/transparentDataEncryption/*",
          "Microsoft.Sql/servers/databases/sqlvulnerabilityAssessments/*",
          "Microsoft.Sql/servers/databases/vulnerabilityAssessments/*",
          "Microsoft.Sql/servers/databases/vulnerabilityAssessmentScans/*",
          "Microsoft.Sql/servers/databases/vulnerabilityAssessmentSettings/*",
          "Microsoft.Sql/servers/devOpsAuditingSettings/*",
          "Microsoft.Sql/servers/firewallRules/*",
          "Microsoft.Sql/servers/read",
          "Microsoft.Sql/servers/securityAlertPolicies/*",
          "Microsoft.Sql/servers/sqlvulnerabilityAssessments/*",
          "Microsoft.Sql/servers/vulnerabilityAssessments/*",
          "Microsoft.Support/*",
          "Microsoft.Sql/servers/azureADOnlyAuthentications/*",
          "Microsoft.Sql/managedInstances/read",
          "Microsoft.Sql/managedInstances/azureADOnlyAuthentications/*",
          "Microsoft.Security/sqlVulnerabilityAssessments/*",
          "Microsoft.Sql/managedInstances/administrators/read",
          "Microsoft.Sql/servers/administrators/read",
          "Microsoft.Sql/servers/databases/ledgerDigestUploads/*",
          "Microsoft.Sql/locations/ledgerDigestUploadsAzureAsyncOperation/read",
          "Microsoft.Sql/locations/ledgerDigestUploadsOperationResults/read",
          "Microsoft.Sql/servers/externalPolicyBasedAuthorizations/*"
        ],
        "notActions": [],
        "dataActions": [],
        "notDataActions": []
      }
    ],
    "createdOn": "2015-06-16T18:44:40.46Z",
    "updatedOn": "2025-10-03T19:16:17.039Z",
    "createdBy": null,
    "updatedBy": null
  },
  "id": "/providers/Microsoft.Authorization/roleDefinitions/056cd41c-7e88-42e1-933e-88ba6a50c9c3",
  "type": "Microsoft.Authorization/roleDefinitions",
  "name": "056cd41c-7e88-42e1-933e-88ba6a50c9c3"
}

Effective Permissions

Operations granted by this role (204 total)

Permission Patterns (from role definition)

Actions 73 patterns
Microsoft.Authorization/*/read Microsoft.Insights/alertRules/* Microsoft.Network/virtualNetworks/subnets/joinViaServiceEndpoint/action Microsoft.ResourceHealth/availabilityStatuses/read Microsoft.Resources/deployments/* Microsoft.Resources/subscriptions/resourceGroups/read Microsoft.Sql/locations/administratorAzureAsyncOperation/read Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/read Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/write Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/read Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/write Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/read Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/write Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/read Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/write Microsoft.Sql/managedInstances/databases/currentSensitivityLabels/* Microsoft.Sql/managedInstances/databases/recommendedSensitivityLabels/* Microsoft.Sql/managedInstances/databases/schemas/tables/columns/sensitivityLabels/* Microsoft.Sql/managedInstances/databases/securityAlertPolicies/* Microsoft.Sql/managedInstances/databases/sensitivityLabels/* Microsoft.Sql/managedInstances/databases/vulnerabilityAssessments/* Microsoft.Sql/servers/advancedThreatProtectionSettings/read Microsoft.Sql/servers/advancedThreatProtectionSettings/write Microsoft.Sql/managedInstances/securityAlertPolicies/* Microsoft.Sql/managedInstances/databases/transparentDataEncryption/* Microsoft.Sql/managedInstances/vulnerabilityAssessments/* Microsoft.Sql/managedInstances/serverConfigurationOptions/read Microsoft.Sql/managedInstances/serverConfigurationOptions/write Microsoft.Sql/locations/serverConfigurationOptionAzureAsyncOperation/read Microsoft.Sql/servers/advancedThreatProtectionSettings/read Microsoft.Sql/servers/advancedThreatProtectionSettings/write Microsoft.Sql/servers/auditingSettings/* Microsoft.Sql/servers/extendedAuditingSettings/* Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/read Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/write Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/read Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/write Microsoft.Sql/servers/databases/auditingSettings/* Microsoft.Sql/servers/databases/auditRecords/read Microsoft.Sql/servers/databases/currentSensitivityLabels/* Microsoft.Sql/servers/databases/dataMaskingPolicies/* Microsoft.Sql/servers/databases/extendedAuditingSettings/read Microsoft.Sql/servers/databases/read Microsoft.Sql/servers/databases/recommendedSensitivityLabels/* Microsoft.Sql/servers/databases/schemas/read Microsoft.Sql/servers/databases/schemas/tables/columns/read Microsoft.Sql/servers/databases/schemas/tables/columns/sensitivityLabels/* Microsoft.Sql/servers/databases/schemas/tables/read Microsoft.Sql/servers/databases/securityAlertPolicies/* Microsoft.Sql/servers/databases/securityMetrics/* Microsoft.Sql/servers/databases/sensitivityLabels/* Microsoft.Sql/servers/databases/transparentDataEncryption/* Microsoft.Sql/servers/databases/sqlvulnerabilityAssessments/* Microsoft.Sql/servers/databases/vulnerabilityAssessments/* Microsoft.Sql/servers/databases/vulnerabilityAssessmentScans/* Microsoft.Sql/servers/databases/vulnerabilityAssessmentSettings/* Microsoft.Sql/servers/devOpsAuditingSettings/* Microsoft.Sql/servers/firewallRules/* Microsoft.Sql/servers/read Microsoft.Sql/servers/securityAlertPolicies/* Microsoft.Sql/servers/sqlvulnerabilityAssessments/* Microsoft.Sql/servers/vulnerabilityAssessments/* Microsoft.Support/* Microsoft.Sql/servers/azureADOnlyAuthentications/* Microsoft.Sql/managedInstances/read Microsoft.Sql/managedInstances/azureADOnlyAuthentications/* Microsoft.Security/sqlVulnerabilityAssessments/* Microsoft.Sql/managedInstances/administrators/read Microsoft.Sql/servers/administrators/read Microsoft.Sql/servers/databases/ledgerDigestUploads/* Microsoft.Sql/locations/ledgerDigestUploadsAzureAsyncOperation/read Microsoft.Sql/locations/ledgerDigestUploadsOperationResults/read Microsoft.Sql/servers/externalPolicyBasedAuthorizations/*

Control Plane Operations (204)

Data Plane Operations (0)

No data plane operations granted