Back to Dashboard

Azure Center for SAP solutions service role

Azure Built-in Role

Role Information

Details and metadata

Role ID
aabbc5dd-1af0-458b-a942-81af88f9c138
Type
BuiltInRole
Last Updated (Azure)
2023-02-03 07:40:23

Change History

Track all modifications to this role

2023-02-03 07:40:23 Initial Scan
View details
{
  "properties": {
    "roleName": "Azure Center for SAP solutions service role",
    "type": "BuiltInRole",
    "description": "Azure Center for SAP solutions service role - This role is intended to be used for providing the permissions to user assigned managed identity. Azure Center for SAP solutions will use this identity to deploy and manage SAP systems.",
    "assignableScopes": [
      "/"
    ],
    "permissions": [
      {
        "actions": [
          "Microsoft.Resources/subscriptions/resourceGroups/write",
          "Microsoft.Resources/subscriptions/resourceGroups/read",
          "Microsoft.Resources/deployments/*",
          "Microsoft.Resources/subscriptions/read",
          "Microsoft.Resources/subscriptions/resourcegroups/deployments/*",
          "Microsoft.Network/loadBalancers/read",
          "Microsoft.Network/loadBalancers/write",
          "Microsoft.Network/loadBalancers/backendAddressPools/read",
          "Microsoft.Network/loadBalancers/backendAddressPools/write",
          "Microsoft.Network/loadBalancers/frontendIPConfigurations/read",
          "Microsoft.Network/loadBalancers/loadBalancingRules/read",
          "Microsoft.Network/loadBalancers/inboundNatRules/read",
          "Microsoft.Network/loadBalancers/providers/Microsoft.Insights/logDefinitions/read",
          "Microsoft.Network/loadBalancers/networkInterfaces/read",
          "Microsoft.Network/loadBalancers/outboundRules/read",
          "Microsoft.Network/loadBalancers/virtualMachines/read",
          "Microsoft.Network/loadBalancers/providers/Microsoft.Insights/metricDefinitions/read",
          "Microsoft.Network/networkInterfaces/read",
          "Microsoft.Network/networkInterfaces/write",
          "Microsoft.Network/networkInterfaces/ipconfigurations/read",
          "Microsoft.Network/networkInterfaces/loadBalancers/read",
          "Microsoft.Network/virtualNetworks/read",
          "Microsoft.Network/virtualNetworks/checkIpAddressAvailability/read",
          "Microsoft.Network/virtualNetworks/subnets/read",
          "Microsoft.Network/virtualNetworks/subnets/virtualMachines/read",
          "Microsoft.Network/virtualNetworks/virtualMachines/read",
          "Microsoft.Network/networkInterfaces/ipconfigurations/join/action",
          "Microsoft.Network/privateEndpoints/read",
          "Microsoft.Network/privateEndpoints/write",
          "Microsoft.Network/networkInterfaces/join/action",
          "Microsoft.Network/loadBalancers/backendAddressPools/join/action",
          "Microsoft.Network/loadBalancers/frontendIPConfigurations/join/action",
          "Microsoft.Network/virtualNetworks/subnets/join/action",
          "Microsoft.Network/virtualNetworks/subnets/joinLoadBalancer/action",
          "Microsoft.Storage/storageAccounts/read",
          "Microsoft.Storage/storageAccounts/write",
          "Microsoft.Storage/storageAccounts/PrivateEndpointConnectionsApproval/action",
          "Microsoft.Storage/storageAccounts/blobServices/read",
          "Microsoft.Storage/storageAccounts/blobServices/containers/read",
          "Microsoft.Storage/storageAccounts/fileServices/read",
          "Microsoft.Storage/storageAccounts/fileServices/write",
          "Microsoft.Storage/storageAccounts/fileServices/shares/read",
          "Microsoft.Storage/storageAccounts/fileServices/shares/write",
          "Microsoft.Compute/virtualMachines/read",
          "Microsoft.Compute/virtualMachines/write",
          "Microsoft.Compute/virtualMachines/instanceView/read",
          "Microsoft.Compute/availabilitySets/read",
          "Microsoft.Compute/availabilitySets/write",
          "Microsoft.Compute/skus/read",
          "Microsoft.Compute/sshPublicKeys/read",
          "Microsoft.Compute/virtualMachines/extensions/read",
          "Microsoft.Compute/virtualMachines/extensions/write",
          "Microsoft.Compute/virtualMachines/extensions/delete",
          "Microsoft.Compute/disks/read",
          "Microsoft.Compute/disks/write"
        ],
        "notActions": [],
        "dataActions": [],
        "notDataActions": []
      }
    ],
    "createdOn": "2022-10-03T15:02:12.784Z",
    "updatedOn": "2023-02-03T07:40:23.801Z",
    "createdBy": null,
    "updatedBy": null
  },
  "id": "/providers/Microsoft.Authorization/roleDefinitions/aabbc5dd-1af0-458b-a942-81af88f9c138",
  "type": "Microsoft.Authorization/roleDefinitions",
  "name": "aabbc5dd-1af0-458b-a942-81af88f9c138"
}

Latest Role JSON

Raw definition from Azure

{
  "properties": {
    "roleName": "Azure Center for SAP solutions service role",
    "type": "BuiltInRole",
    "description": "Azure Center for SAP solutions service role - This role is intended to be used for providing the permissions to user assigned managed identity. Azure Center for SAP solutions will use this identity to deploy and manage SAP systems.",
    "assignableScopes": [
      "/"
    ],
    "permissions": [
      {
        "actions": [
          "Microsoft.Resources/subscriptions/resourceGroups/write",
          "Microsoft.Resources/subscriptions/resourceGroups/read",
          "Microsoft.Resources/deployments/*",
          "Microsoft.Resources/subscriptions/read",
          "Microsoft.Resources/subscriptions/resourcegroups/deployments/*",
          "Microsoft.Network/loadBalancers/read",
          "Microsoft.Network/loadBalancers/write",
          "Microsoft.Network/loadBalancers/backendAddressPools/read",
          "Microsoft.Network/loadBalancers/backendAddressPools/write",
          "Microsoft.Network/loadBalancers/frontendIPConfigurations/read",
          "Microsoft.Network/loadBalancers/loadBalancingRules/read",
          "Microsoft.Network/loadBalancers/inboundNatRules/read",
          "Microsoft.Network/loadBalancers/providers/Microsoft.Insights/logDefinitions/read",
          "Microsoft.Network/loadBalancers/networkInterfaces/read",
          "Microsoft.Network/loadBalancers/outboundRules/read",
          "Microsoft.Network/loadBalancers/virtualMachines/read",
          "Microsoft.Network/loadBalancers/providers/Microsoft.Insights/metricDefinitions/read",
          "Microsoft.Network/networkInterfaces/read",
          "Microsoft.Network/networkInterfaces/write",
          "Microsoft.Network/networkInterfaces/ipconfigurations/read",
          "Microsoft.Network/networkInterfaces/loadBalancers/read",
          "Microsoft.Network/virtualNetworks/read",
          "Microsoft.Network/virtualNetworks/checkIpAddressAvailability/read",
          "Microsoft.Network/virtualNetworks/subnets/read",
          "Microsoft.Network/virtualNetworks/subnets/virtualMachines/read",
          "Microsoft.Network/virtualNetworks/virtualMachines/read",
          "Microsoft.Network/networkInterfaces/ipconfigurations/join/action",
          "Microsoft.Network/privateEndpoints/read",
          "Microsoft.Network/privateEndpoints/write",
          "Microsoft.Network/networkInterfaces/join/action",
          "Microsoft.Network/loadBalancers/backendAddressPools/join/action",
          "Microsoft.Network/loadBalancers/frontendIPConfigurations/join/action",
          "Microsoft.Network/virtualNetworks/subnets/join/action",
          "Microsoft.Network/virtualNetworks/subnets/joinLoadBalancer/action",
          "Microsoft.Storage/storageAccounts/read",
          "Microsoft.Storage/storageAccounts/write",
          "Microsoft.Storage/storageAccounts/PrivateEndpointConnectionsApproval/action",
          "Microsoft.Storage/storageAccounts/blobServices/read",
          "Microsoft.Storage/storageAccounts/blobServices/containers/read",
          "Microsoft.Storage/storageAccounts/fileServices/read",
          "Microsoft.Storage/storageAccounts/fileServices/write",
          "Microsoft.Storage/storageAccounts/fileServices/shares/read",
          "Microsoft.Storage/storageAccounts/fileServices/shares/write",
          "Microsoft.Compute/virtualMachines/read",
          "Microsoft.Compute/virtualMachines/write",
          "Microsoft.Compute/virtualMachines/instanceView/read",
          "Microsoft.Compute/availabilitySets/read",
          "Microsoft.Compute/availabilitySets/write",
          "Microsoft.Compute/skus/read",
          "Microsoft.Compute/sshPublicKeys/read",
          "Microsoft.Compute/virtualMachines/extensions/read",
          "Microsoft.Compute/virtualMachines/extensions/write",
          "Microsoft.Compute/virtualMachines/extensions/delete",
          "Microsoft.Compute/disks/read",
          "Microsoft.Compute/disks/write"
        ],
        "notActions": [],
        "dataActions": [],
        "notDataActions": []
      }
    ],
    "createdOn": "2022-10-03T15:02:12.784Z",
    "updatedOn": "2023-02-03T07:40:23.801Z",
    "createdBy": null,
    "updatedBy": null
  },
  "id": "/providers/Microsoft.Authorization/roleDefinitions/aabbc5dd-1af0-458b-a942-81af88f9c138",
  "type": "Microsoft.Authorization/roleDefinitions",
  "name": "aabbc5dd-1af0-458b-a942-81af88f9c138"
}

Effective Permissions

Operations granted by this role (66 total)

Permission Patterns (from role definition)

Actions 55 patterns
Microsoft.Resources/subscriptions/resourceGroups/write Microsoft.Resources/subscriptions/resourceGroups/read Microsoft.Resources/deployments/* Microsoft.Resources/subscriptions/read Microsoft.Resources/subscriptions/resourcegroups/deployments/* Microsoft.Network/loadBalancers/read Microsoft.Network/loadBalancers/write Microsoft.Network/loadBalancers/backendAddressPools/read Microsoft.Network/loadBalancers/backendAddressPools/write Microsoft.Network/loadBalancers/frontendIPConfigurations/read Microsoft.Network/loadBalancers/loadBalancingRules/read Microsoft.Network/loadBalancers/inboundNatRules/read Microsoft.Network/loadBalancers/providers/Microsoft.Insights/logDefinitions/read Microsoft.Network/loadBalancers/networkInterfaces/read Microsoft.Network/loadBalancers/outboundRules/read Microsoft.Network/loadBalancers/virtualMachines/read Microsoft.Network/loadBalancers/providers/Microsoft.Insights/metricDefinitions/read Microsoft.Network/networkInterfaces/read Microsoft.Network/networkInterfaces/write Microsoft.Network/networkInterfaces/ipconfigurations/read Microsoft.Network/networkInterfaces/loadBalancers/read Microsoft.Network/virtualNetworks/read Microsoft.Network/virtualNetworks/checkIpAddressAvailability/read Microsoft.Network/virtualNetworks/subnets/read Microsoft.Network/virtualNetworks/subnets/virtualMachines/read Microsoft.Network/virtualNetworks/virtualMachines/read Microsoft.Network/networkInterfaces/ipconfigurations/join/action Microsoft.Network/privateEndpoints/read Microsoft.Network/privateEndpoints/write Microsoft.Network/networkInterfaces/join/action Microsoft.Network/loadBalancers/backendAddressPools/join/action Microsoft.Network/loadBalancers/frontendIPConfigurations/join/action Microsoft.Network/virtualNetworks/subnets/join/action Microsoft.Network/virtualNetworks/subnets/joinLoadBalancer/action Microsoft.Storage/storageAccounts/read Microsoft.Storage/storageAccounts/write Microsoft.Storage/storageAccounts/PrivateEndpointConnectionsApproval/action Microsoft.Storage/storageAccounts/blobServices/read Microsoft.Storage/storageAccounts/blobServices/containers/read Microsoft.Storage/storageAccounts/fileServices/read Microsoft.Storage/storageAccounts/fileServices/write Microsoft.Storage/storageAccounts/fileServices/shares/read Microsoft.Storage/storageAccounts/fileServices/shares/write Microsoft.Compute/virtualMachines/read Microsoft.Compute/virtualMachines/write Microsoft.Compute/virtualMachines/instanceView/read Microsoft.Compute/availabilitySets/read Microsoft.Compute/availabilitySets/write Microsoft.Compute/skus/read Microsoft.Compute/sshPublicKeys/read Microsoft.Compute/virtualMachines/extensions/read Microsoft.Compute/virtualMachines/extensions/write Microsoft.Compute/virtualMachines/extensions/delete Microsoft.Compute/disks/read Microsoft.Compute/disks/write

Control Plane Operations (66)

Data Plane Operations (0)

No data plane operations granted