last sync: 2025-Aug-01 17:22:47 UTC

Azure Red Hat OpenShift File Storage Operator

Azure BuiltIn RBAC Role definition

NameAzure Red Hat OpenShift File Storage Operator
Microsoft Learn
Id0d7aedc0-15fd-4a67-a412-efad370c947e
DescriptionInstall Container Storage Interface (CSI) drivers that enable your cluster to use Azure Files. Set OpenShift cluster-wide storage defaults to ensure a default storageclass exists for clusters.
CategoryContainers
Microsoft Learn
CreatedOn2024-01-31 16:20:01 UTC
UpdatedOn2025-07-28 15:04:34 UTC
Permissions summary Effective control plane and data plane operations: 30 (unique operations)
•action: 11
•delete: 2
•read: 10
•write: 7

Actions: 30
Resolved control plane operations from Actions: 30
Effective control plane operations: 30
•action: 11
•delete: 2
•read: 10
•write: 7

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 16864

DataActions: 0
Resolved data plane operations: 0
Effective data plane operations: 0

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3587
Actions
Operation Description
Microsoft.Network/locations/operations/readGets operation resource that represents status of an asynchronous operation
Microsoft.Network/natGateways/join/actionJoins a NAT Gateway
Microsoft.Network/networkIntentPolicies/join/actionJoins a Network Intent Policy. Not alertable.
Microsoft.Network/networkManagers/ipamPools/associateResourcesToPool/actionAction permission for associate resources to Ipam Pool
Microsoft.Network/networkSecurityGroups/join/actionJoins a network security group. Not Alertable.
Microsoft.Network/privateDnsOperationStatuses/readGets status of a Private DNS operation
Microsoft.Network/privateDnsZones/join/actionJoins a Private DNS Zone
Microsoft.Network/privateDnsZones/readGet the Private DNS zone properties, in JSON format. Note that this command does not retrieve the virtual networks to which the Private DNS zone is linked or the record sets contained within the zone.
Microsoft.Network/privateDnsZones/virtualNetworkLinks/readGet the Private DNS zone link to virtual network properties, in JSON format.
Microsoft.Network/privateDnsZones/virtualNetworkLinks/writeCreate or update a Private DNS zone link to virtual network.
Microsoft.Network/privateDnsZones/writeCreate or update a Private DNS zone within a resource group. Note that this command cannot be used to create or update virtual network links or record sets within the zone.
Microsoft.Network/privateEndpoints/privateDnsZoneGroups/readGets a Private DNS Zone Group
Microsoft.Network/privateEndpoints/privateDnsZoneGroups/writePuts a Private DNS Zone Group
Microsoft.Network/privateEndpoints/readGets an private endpoint resource.
Microsoft.Network/privateEndpoints/writeCreates a new private endpoint, or updates an existing private endpoint.
Microsoft.Network/routeTables/join/actionJoins a route table. Not Alertable.
Microsoft.Network/serviceEndpointPolicies/join/actionJoins a Service Endpoint Policy. Not alertable.
Microsoft.Network/virtualNetworks/join/actionJoins a virtual network. Not Alertable.
Microsoft.Network/virtualNetworks/subnets/join/actionJoins a virtual network. Not Alertable.
Microsoft.Network/virtualNetworks/subnets/readGets a virtual network subnet definition
Microsoft.Network/virtualNetworks/subnets/writeCreates a virtual network subnet or updates an existing virtual network subnet
Microsoft.Storage/storageAccounts/deleteDeletes an existing storage account.
Microsoft.Storage/storageAccounts/fileServices/readGet file service properties
Microsoft.Storage/storageAccounts/fileServices/shares/deleteDelete file share
Microsoft.Storage/storageAccounts/fileServices/shares/readList file shares
Microsoft.Storage/storageAccounts/fileServices/shares/writeCreate or update file share
Microsoft.Storage/storageAccounts/listKeys/actionReturns the access keys for the specified storage account.
Microsoft.Storage/storageAccounts/PrivateEndpointConnectionsApproval/actionApprove Private Endpoint Connections
Microsoft.Storage/storageAccounts/readReturns the list of storage accounts or gets the properties for the specified storage account.
Microsoft.Storage/storageAccounts/writeCreates a storage account with the specified parameters or update the properties or tags or adds custom domain for the specified storage account.
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in
BuiltIn Policy
none
History
Date/Time (UTC ymd) (i) Change Change detail
2025-07-28 17:33:19 change: Actions Actions: 'add Microsoft.Storage/storageAccounts/PrivateEndpointConnectionsApproval/action; add Microsoft.Network/virtualNetworks/join/action; add Microsoft.Network/virtualNetworks/subnets/join/action; add Microsoft.Network/privateEndpoints/write; add Microsoft.Network/networkManagers/ipamPools/associateResourcesToPool/action; add Microsoft.Network/networkIntentPolicies/join/action; add Microsoft.Network/serviceEndpointPolicies/join/action; add Microsoft.Network/locations/operations/read; add Microsoft.Network/privateDnsOperationStatuses/read; add Microsoft.Network/privateDnsZones/read; add Microsoft.Network/privateDnsZones/virtualNetworkLinks/read; add Microsoft.Network/privateDnsZones/virtualNetworkLinks/write; add Microsoft.Network/privateDnsZones/write; add Microsoft.Network/privateDnsZones/join/action; add Microsoft.Network/privateEndpoints/privateDnsZoneGroups/write; add Microsoft.Network/privateEndpoints/privateDnsZoneGroups/read; add Microsoft.Network/privateEndpoints/read'
2025-03-11 18:29:19 change: DisplayName, Actions New DisplayName: 'Azure Red Hat OpenShift File Storage Operator'
Old DisplayName: 'Azure RedHat OpenShift Azure Files Storage Operator Role',
Actions: 'add Microsoft.Network/routeTables/join/action; add Microsoft.Network/natGateways/join/action'
2024-04-15 17:47:24 change: Actions Actions: 'add Microsoft.Storage/storageAccounts/delete; add Microsoft.Storage/storageAccounts/fileServices/read; add Microsoft.Storage/storageAccounts/fileServices/shares/delete; add Microsoft.Storage/storageAccounts/fileServices/shares/read; add Microsoft.Storage/storageAccounts/fileServices/shares/write; add Microsoft.Storage/storageAccounts/listKeys/action; add Microsoft.Storage/storageAccounts/read; add Microsoft.Storage/storageAccounts/write; add Microsoft.Network/networkSecurityGroups/join/action; add Microsoft.Network/virtualNetworks/subnets/read; add Microsoft.Network/virtualNetworks/subnets/write'
2024-01-31 19:57:40 add: Role 0d7aedc0-15fd-4a67-a412-efad370c947e
JSON
api-version=2023-07-01-preview
Condition none