Role Information
Details and metadata
a35466a1-cfd6-450a-b35e-683fcdf30363
Change History
Track all modifications to this role since 2025-12-15 01:08:16+00:00
Updated On
Event Type
Summary & Details
2025-02-14 16:23:19
Initial Scan
Show full JSON
{
"properties": {
"roleName": "Azure Batch Service Orchestration Role",
"type": "BuiltInRole",
"description": "Grants the required permissions to Azure Batch Resource Provider to manage compute and other backing resources in the subscription.",
"assignableScopes": [
"/"
],
"permissions": [
{
"actions": [
"Microsoft.Security/assessments/read",
"Microsoft.AzureFleet/fleets/write",
"Microsoft.AzureFleet/fleets/read",
"Microsoft.AzureFleet/fleets/delete",
"Microsoft.Compute/locations/DiskOperations/read",
"Microsoft.Compute/locations/operations/read",
"Microsoft.Compute/virtualMachineScaleSets/approveRollingUpgrade/action",
"Microsoft.Compute/virtualMachineScaleSets/deallocate/action",
"Microsoft.Compute/virtualMachineScaleSets/delete",
"Microsoft.Compute/virtualMachineScaleSets/delete/action",
"Microsoft.Compute/VirtualMachineScaleSets/read",
"Microsoft.Compute/virtualMachineScaleSets/reimage/action",
"Microsoft.Compute/virtualMachineScaleSets/reimageall/action",
"Microsoft.Compute/virtualMachineScaleSets/restart/action",
"Microsoft.Compute/virtualMachineScaleSets/start/action",
"Microsoft.Compute/virtualMachineScaleSets/write",
"Microsoft.Compute/virtualMachineScaleSets/extensions/read",
"microsoft.Compute/virtualMachineScaleSets/networkInterfaces/read",
"Microsoft.Compute/virtualMachineScaleSets/virtualMachines/read",
"Microsoft.Compute/virtualMachineScaleSets/virtualmachines/restart/action",
"Microsoft.Compute/diskEncryptionSets/read",
"Microsoft.Insights/alertRules/*",
"Microsoft.Insights/dataCollectionRuleAssociations/read",
"Microsoft.Resources/deployments/*",
"Microsoft.Insights/diagnosticSettings/read",
"Microsoft.Resources/subscriptions/read",
"Microsoft.Resources/subscriptions/operationresults/read",
"Microsoft.Resources/subscriptions/resourceGroups/read",
"Microsoft.Resources/subscriptions/resourceGroups/delete",
"Microsoft.Resources/subscriptions/resourceGroups/write",
"Microsoft.Resources/subscriptions/resourceGroups/resources/read",
"Microsoft.Network/networkWatchers/read",
"Microsoft.Network/virtualNetworks/delete",
"Microsoft.Network/virtualNetworks/write"
],
"notActions": [],
"dataActions": [],
"notDataActions": []
}
],
"createdOn": "2024-09-24T15:12:33.827Z",
"updatedOn": "2025-02-14T16:23:19.448Z",
"createdBy": null,
"updatedBy": null
},
"id": "/providers/Microsoft.Authorization/roleDefinitions/a35466a1-cfd6-450a-b35e-683fcdf30363",
"type": "Microsoft.Authorization/roleDefinitions",
"name": "a35466a1-cfd6-450a-b35e-683fcdf30363"
}
2025-02-14 16:23:19
Initial Scan
View details
{
"properties": {
"roleName": "Azure Batch Service Orchestration Role",
"type": "BuiltInRole",
"description": "Grants the required permissions to Azure Batch Resource Provider to manage compute and other backing resources in the subscription.",
"assignableScopes": [
"/"
],
"permissions": [
{
"actions": [
"Microsoft.Security/assessments/read",
"Microsoft.AzureFleet/fleets/write",
"Microsoft.AzureFleet/fleets/read",
"Microsoft.AzureFleet/fleets/delete",
"Microsoft.Compute/locations/DiskOperations/read",
"Microsoft.Compute/locations/operations/read",
"Microsoft.Compute/virtualMachineScaleSets/approveRollingUpgrade/action",
"Microsoft.Compute/virtualMachineScaleSets/deallocate/action",
"Microsoft.Compute/virtualMachineScaleSets/delete",
"Microsoft.Compute/virtualMachineScaleSets/delete/action",
"Microsoft.Compute/VirtualMachineScaleSets/read",
"Microsoft.Compute/virtualMachineScaleSets/reimage/action",
"Microsoft.Compute/virtualMachineScaleSets/reimageall/action",
"Microsoft.Compute/virtualMachineScaleSets/restart/action",
"Microsoft.Compute/virtualMachineScaleSets/start/action",
"Microsoft.Compute/virtualMachineScaleSets/write",
"Microsoft.Compute/virtualMachineScaleSets/extensions/read",
"microsoft.Compute/virtualMachineScaleSets/networkInterfaces/read",
"Microsoft.Compute/virtualMachineScaleSets/virtualMachines/read",
"Microsoft.Compute/virtualMachineScaleSets/virtualmachines/restart/action",
"Microsoft.Compute/diskEncryptionSets/read",
"Microsoft.Insights/alertRules/*",
"Microsoft.Insights/dataCollectionRuleAssociations/read",
"Microsoft.Resources/deployments/*",
"Microsoft.Insights/diagnosticSettings/read",
"Microsoft.Resources/subscriptions/read",
"Microsoft.Resources/subscriptions/operationresults/read",
"Microsoft.Resources/subscriptions/resourceGroups/read",
"Microsoft.Resources/subscriptions/resourceGroups/delete",
"Microsoft.Resources/subscriptions/resourceGroups/write",
"Microsoft.Resources/subscriptions/resourceGroups/resources/read",
"Microsoft.Network/networkWatchers/read",
"Microsoft.Network/virtualNetworks/delete",
"Microsoft.Network/virtualNetworks/write"
],
"notActions": [],
"dataActions": [],
"notDataActions": []
}
],
"createdOn": "2024-09-24T15:12:33.827Z",
"updatedOn": "2025-02-14T16:23:19.448Z",
"createdBy": null,
"updatedBy": null
},
"id": "/providers/Microsoft.Authorization/roleDefinitions/a35466a1-cfd6-450a-b35e-683fcdf30363",
"type": "Microsoft.Authorization/roleDefinitions",
"name": "a35466a1-cfd6-450a-b35e-683fcdf30363"
}
Latest Role JSON
Raw definition from Azure
{
"properties": {
"roleName": "Azure Batch Service Orchestration Role",
"type": "BuiltInRole",
"description": "Grants the required permissions to Azure Batch Resource Provider to manage compute and other backing resources in the subscription.",
"assignableScopes": [
"/"
],
"permissions": [
{
"actions": [
"Microsoft.Security/assessments/read",
"Microsoft.AzureFleet/fleets/write",
"Microsoft.AzureFleet/fleets/read",
"Microsoft.AzureFleet/fleets/delete",
"Microsoft.Compute/locations/DiskOperations/read",
"Microsoft.Compute/locations/operations/read",
"Microsoft.Compute/virtualMachineScaleSets/approveRollingUpgrade/action",
"Microsoft.Compute/virtualMachineScaleSets/deallocate/action",
"Microsoft.Compute/virtualMachineScaleSets/delete",
"Microsoft.Compute/virtualMachineScaleSets/delete/action",
"Microsoft.Compute/VirtualMachineScaleSets/read",
"Microsoft.Compute/virtualMachineScaleSets/reimage/action",
"Microsoft.Compute/virtualMachineScaleSets/reimageall/action",
"Microsoft.Compute/virtualMachineScaleSets/restart/action",
"Microsoft.Compute/virtualMachineScaleSets/start/action",
"Microsoft.Compute/virtualMachineScaleSets/write",
"Microsoft.Compute/virtualMachineScaleSets/extensions/read",
"microsoft.Compute/virtualMachineScaleSets/networkInterfaces/read",
"Microsoft.Compute/virtualMachineScaleSets/virtualMachines/read",
"Microsoft.Compute/virtualMachineScaleSets/virtualmachines/restart/action",
"Microsoft.Compute/diskEncryptionSets/read",
"Microsoft.Insights/alertRules/*",
"Microsoft.Insights/dataCollectionRuleAssociations/read",
"Microsoft.Resources/deployments/*",
"Microsoft.Insights/diagnosticSettings/read",
"Microsoft.Resources/subscriptions/read",
"Microsoft.Resources/subscriptions/operationresults/read",
"Microsoft.Resources/subscriptions/resourceGroups/read",
"Microsoft.Resources/subscriptions/resourceGroups/delete",
"Microsoft.Resources/subscriptions/resourceGroups/write",
"Microsoft.Resources/subscriptions/resourceGroups/resources/read",
"Microsoft.Network/networkWatchers/read",
"Microsoft.Network/virtualNetworks/delete",
"Microsoft.Network/virtualNetworks/write"
],
"notActions": [],
"dataActions": [],
"notDataActions": []
}
],
"createdOn": "2024-09-24T15:12:33.827Z",
"updatedOn": "2025-02-14T16:23:19.448Z",
"createdBy": null,
"updatedBy": null
},
"id": "/providers/Microsoft.Authorization/roleDefinitions/a35466a1-cfd6-450a-b35e-683fcdf30363",
"type": "Microsoft.Authorization/roleDefinitions",
"name": "a35466a1-cfd6-450a-b35e-683fcdf30363"
}
Effective Permissions
Operations granted by this role (40 total)
Permission Patterns (from role definition)
Actions
34 patterns
Microsoft.Security/assessments/read
Microsoft.AzureFleet/fleets/write
Microsoft.AzureFleet/fleets/read
Microsoft.AzureFleet/fleets/delete
Microsoft.Compute/locations/DiskOperations/read
Microsoft.Compute/locations/operations/read
Microsoft.Compute/virtualMachineScaleSets/approveRollingUpgrade/action
Microsoft.Compute/virtualMachineScaleSets/deallocate/action
Microsoft.Compute/virtualMachineScaleSets/delete
Microsoft.Compute/virtualMachineScaleSets/delete/action
Microsoft.Compute/VirtualMachineScaleSets/read
Microsoft.Compute/virtualMachineScaleSets/reimage/action
Microsoft.Compute/virtualMachineScaleSets/reimageall/action
Microsoft.Compute/virtualMachineScaleSets/restart/action
Microsoft.Compute/virtualMachineScaleSets/start/action
Microsoft.Compute/virtualMachineScaleSets/write
Microsoft.Compute/virtualMachineScaleSets/extensions/read
microsoft.Compute/virtualMachineScaleSets/networkInterfaces/read
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/read
Microsoft.Compute/virtualMachineScaleSets/virtualmachines/restart/action
Microsoft.Compute/diskEncryptionSets/read
Microsoft.Insights/alertRules/*
Microsoft.Insights/dataCollectionRuleAssociations/read
Microsoft.Resources/deployments/*
Microsoft.Insights/diagnosticSettings/read
Microsoft.Resources/subscriptions/read
Microsoft.Resources/subscriptions/operationresults/read
Microsoft.Resources/subscriptions/resourceGroups/read
Microsoft.Resources/subscriptions/resourceGroups/delete
Microsoft.Resources/subscriptions/resourceGroups/write
Microsoft.Resources/subscriptions/resourceGroups/resources/read
Microsoft.Network/networkWatchers/read
Microsoft.Network/virtualNetworks/delete
Microsoft.Network/virtualNetworks/write
Control Plane Operations (40)
No matching operations
/ shown
Data Plane Operations (0)
No data plane operations granted