Role Information
Details and metadata
3498e952-d568-435e-9b2c-8d77e338d7f7
Change History
Track all modifications to this role
Updated On
Event Type
Summary & Details
2023-05-09 20:26:01
Initial Scan
Show full JSON
{
"properties": {
"roleName": "Azure Kubernetes Service RBAC Admin",
"type": "BuiltInRole",
"description": "Lets you manage all resources under cluster/namespace, except update or delete resource quotas and namespaces.",
"assignableScopes": [
"/"
],
"permissions": [
{
"actions": [
"Microsoft.Authorization/*/read",
"Microsoft.Resources/subscriptions/operationresults/read",
"Microsoft.Resources/subscriptions/read",
"Microsoft.Resources/subscriptions/resourceGroups/read",
"Microsoft.ContainerService/managedClusters/listClusterUserCredential/action"
],
"notActions": [],
"dataActions": [
"Microsoft.ContainerService/managedClusters/*"
],
"notDataActions": [
"Microsoft.ContainerService/managedClusters/resourcequotas/write",
"Microsoft.ContainerService/managedClusters/resourcequotas/delete",
"Microsoft.ContainerService/managedClusters/namespaces/write",
"Microsoft.ContainerService/managedClusters/namespaces/delete"
]
}
],
"createdOn": "2020-07-02T17:50:30.402Z",
"updatedOn": "2023-05-09T20:26:01.376Z",
"createdBy": null,
"updatedBy": null
},
"id": "/providers/Microsoft.Authorization/roleDefinitions/3498e952-d568-435e-9b2c-8d77e338d7f7",
"type": "Microsoft.Authorization/roleDefinitions",
"name": "3498e952-d568-435e-9b2c-8d77e338d7f7"
}
2023-05-09 20:26:01
Initial Scan
View details
{
"properties": {
"roleName": "Azure Kubernetes Service RBAC Admin",
"type": "BuiltInRole",
"description": "Lets you manage all resources under cluster/namespace, except update or delete resource quotas and namespaces.",
"assignableScopes": [
"/"
],
"permissions": [
{
"actions": [
"Microsoft.Authorization/*/read",
"Microsoft.Resources/subscriptions/operationresults/read",
"Microsoft.Resources/subscriptions/read",
"Microsoft.Resources/subscriptions/resourceGroups/read",
"Microsoft.ContainerService/managedClusters/listClusterUserCredential/action"
],
"notActions": [],
"dataActions": [
"Microsoft.ContainerService/managedClusters/*"
],
"notDataActions": [
"Microsoft.ContainerService/managedClusters/resourcequotas/write",
"Microsoft.ContainerService/managedClusters/resourcequotas/delete",
"Microsoft.ContainerService/managedClusters/namespaces/write",
"Microsoft.ContainerService/managedClusters/namespaces/delete"
]
}
],
"createdOn": "2020-07-02T17:50:30.402Z",
"updatedOn": "2023-05-09T20:26:01.376Z",
"createdBy": null,
"updatedBy": null
},
"id": "/providers/Microsoft.Authorization/roleDefinitions/3498e952-d568-435e-9b2c-8d77e338d7f7",
"type": "Microsoft.Authorization/roleDefinitions",
"name": "3498e952-d568-435e-9b2c-8d77e338d7f7"
}
Latest Role JSON
Raw definition from Azure
{
"properties": {
"roleName": "Azure Kubernetes Service RBAC Admin",
"type": "BuiltInRole",
"description": "Lets you manage all resources under cluster/namespace, except update or delete resource quotas and namespaces.",
"assignableScopes": [
"/"
],
"permissions": [
{
"actions": [
"Microsoft.Authorization/*/read",
"Microsoft.Resources/subscriptions/operationresults/read",
"Microsoft.Resources/subscriptions/read",
"Microsoft.Resources/subscriptions/resourceGroups/read",
"Microsoft.ContainerService/managedClusters/listClusterUserCredential/action"
],
"notActions": [],
"dataActions": [
"Microsoft.ContainerService/managedClusters/*"
],
"notDataActions": [
"Microsoft.ContainerService/managedClusters/resourcequotas/write",
"Microsoft.ContainerService/managedClusters/resourcequotas/delete",
"Microsoft.ContainerService/managedClusters/namespaces/write",
"Microsoft.ContainerService/managedClusters/namespaces/delete"
]
}
],
"createdOn": "2020-07-02T17:50:30.402Z",
"updatedOn": "2023-05-09T20:26:01.376Z",
"createdBy": null,
"updatedBy": null
},
"id": "/providers/Microsoft.Authorization/roleDefinitions/3498e952-d568-435e-9b2c-8d77e338d7f7",
"type": "Microsoft.Authorization/roleDefinitions",
"name": "3498e952-d568-435e-9b2c-8d77e338d7f7"
}
Effective Permissions
Operations granted by this role (414 total)
Permission Patterns (from role definition)
Actions
5 patterns
Microsoft.Authorization/*/read
Microsoft.Resources/subscriptions/operationresults/read
Microsoft.Resources/subscriptions/read
Microsoft.Resources/subscriptions/resourceGroups/read
Microsoft.ContainerService/managedClusters/listClusterUserCredential/action
Data Actions
1 pattern
Microsoft.ContainerService/managedClusters/*
NotDataActions (excluded)
Microsoft.ContainerService/managedClusters/resourcequotas/write
Microsoft.ContainerService/managedClusters/resourcequotas/delete
Microsoft.ContainerService/managedClusters/namespaces/write
Microsoft.ContainerService/managedClusters/namespaces/delete
Control Plane Operations (35)
No matching operations
/ shown
Data Plane Operations (379)
No matching operations
/ shown