Role Information
Details and metadata
18ab4d3d-a1bf-4477-8ad9-8359bc988f69
Change History
Track all modifications to this role since 2025-12-15 01:08:16+00:00
Updated On
Event Type
Summary & Details
2025-11-17 16:01:34
Initial Scan
Show full JSON
{
"properties": {
"roleName": "Azure Kubernetes Fleet Manager RBAC Cluster Admin",
"type": "BuiltInRole",
"description": "Grants read/write access to all Kubernetes resources in the fleet-managed hub cluster.",
"assignableScopes": [
"/"
],
"permissions": [
{
"actions": [
"Microsoft.Authorization/*/read",
"Microsoft.Resources/subscriptions/operationresults/read",
"Microsoft.Resources/subscriptions/read",
"Microsoft.Resources/subscriptions/resourceGroups/read",
"Microsoft.ContainerService/fleets/read",
"Microsoft.ContainerService/fleets/listCredentials/action"
],
"notActions": [],
"dataActions": [
"Microsoft.ContainerService/fleets/*"
],
"notDataActions": [
"Microsoft.ContainerService/fleets/members/*"
]
}
],
"createdOn": "2022-08-22T15:27:28.667Z",
"updatedOn": "2025-11-17T16:01:34.386Z",
"createdBy": null,
"updatedBy": null
},
"id": "/providers/Microsoft.Authorization/roleDefinitions/18ab4d3d-a1bf-4477-8ad9-8359bc988f69",
"type": "Microsoft.Authorization/roleDefinitions",
"name": "18ab4d3d-a1bf-4477-8ad9-8359bc988f69"
}
2025-11-17 16:01:34
Initial Scan
View details
{
"properties": {
"roleName": "Azure Kubernetes Fleet Manager RBAC Cluster Admin",
"type": "BuiltInRole",
"description": "Grants read/write access to all Kubernetes resources in the fleet-managed hub cluster.",
"assignableScopes": [
"/"
],
"permissions": [
{
"actions": [
"Microsoft.Authorization/*/read",
"Microsoft.Resources/subscriptions/operationresults/read",
"Microsoft.Resources/subscriptions/read",
"Microsoft.Resources/subscriptions/resourceGroups/read",
"Microsoft.ContainerService/fleets/read",
"Microsoft.ContainerService/fleets/listCredentials/action"
],
"notActions": [],
"dataActions": [
"Microsoft.ContainerService/fleets/*"
],
"notDataActions": [
"Microsoft.ContainerService/fleets/members/*"
]
}
],
"createdOn": "2022-08-22T15:27:28.667Z",
"updatedOn": "2025-11-17T16:01:34.386Z",
"createdBy": null,
"updatedBy": null
},
"id": "/providers/Microsoft.Authorization/roleDefinitions/18ab4d3d-a1bf-4477-8ad9-8359bc988f69",
"type": "Microsoft.Authorization/roleDefinitions",
"name": "18ab4d3d-a1bf-4477-8ad9-8359bc988f69"
}
Latest Role JSON
Raw definition from Azure
{
"properties": {
"roleName": "Azure Kubernetes Fleet Manager RBAC Cluster Admin",
"type": "BuiltInRole",
"description": "Grants read/write access to all Kubernetes resources in the fleet-managed hub cluster.",
"assignableScopes": [
"/"
],
"permissions": [
{
"actions": [
"Microsoft.Authorization/*/read",
"Microsoft.Resources/subscriptions/operationresults/read",
"Microsoft.Resources/subscriptions/read",
"Microsoft.Resources/subscriptions/resourceGroups/read",
"Microsoft.ContainerService/fleets/read",
"Microsoft.ContainerService/fleets/listCredentials/action"
],
"notActions": [],
"dataActions": [
"Microsoft.ContainerService/fleets/*"
],
"notDataActions": [
"Microsoft.ContainerService/fleets/members/*"
]
}
],
"createdOn": "2022-08-22T15:27:28.667Z",
"updatedOn": "2025-11-17T16:01:34.386Z",
"createdBy": null,
"updatedBy": null
},
"id": "/providers/Microsoft.Authorization/roleDefinitions/18ab4d3d-a1bf-4477-8ad9-8359bc988f69",
"type": "Microsoft.Authorization/roleDefinitions",
"name": "18ab4d3d-a1bf-4477-8ad9-8359bc988f69"
}
Effective Permissions
Operations granted by this role (391 total)
Permission Patterns (from role definition)
Actions
6 patterns
Microsoft.Authorization/*/read
Microsoft.Resources/subscriptions/operationresults/read
Microsoft.Resources/subscriptions/read
Microsoft.Resources/subscriptions/resourceGroups/read
Microsoft.ContainerService/fleets/read
Microsoft.ContainerService/fleets/listCredentials/action
Data Actions
1 pattern
Microsoft.ContainerService/fleets/*
NotDataActions (excluded)
Microsoft.ContainerService/fleets/members/*