last sync: 2025-Oct-31 18:22:44 UTC

Service Group Administrator

Azure BuiltIn RBAC Role definition

NameService Group Administrator
Microsoft Learn
Id4e50c84c-c78e-4e37-b47e-e60ffea0a775
DescriptionRole Definition for administrator of a Service Group
CategoryManagement and governance
Microsoft Learn
CreatedOn2024-10-17 18:32:17 UTC
UpdatedOn2025-10-30 18:51:00 UTC
Assignable scopes /providers/Microsoft.Management/serviceGroups
Permissions summary Effective control plane and data plane operations: 17431 (unique operations)
•: 1
•action: 3969
•delete: 2680
•read: 7449
•read : 1
•write: 3331

Actions: 3
Resolved control plane operations from Actions: 17433
Effective control plane operations: 17431
•: 1
•action: 3969
•delete: 2680
•read: 7449
•read : 1
•write: 3331

NotActions: 2
Resolved control plane operations from NotActions: 2
Effective denied control plane operations: 2

DataActions: 0
Resolved data plane operations: 0
Effective data plane operations: 0

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 4078
Actions
Operation Description
*wildcarded / no description
Microsoft.Authorization/roleAssignments/delete conditionedDelete a role assignment at the specified scope.
Microsoft.Authorization/roleAssignments/write conditionedCreate a role assignment at the specified scope.
NotActions
Operation Description
Microsoft.Authorization/roleAssignments/deleteDelete a role assignment at the specified scope.
Microsoft.Authorization/roleAssignments/writeCreate a role assignment at the specified scope.
DataActions n/a
NotDataActions n/a
Used in
BuiltIn Policy
none
History
Date/Time (UTC ymd) (i) Change Change detail
2024-10-18 17:51:46 add: Role 4e50c84c-c78e-4e37-b47e-e60ffea0a775
JSON
api-version=2023-07-01-preview
Condition
    
    (
        (
            !
            (
                ActionMatches {
                'Microsoft.Authorization/roleAssignments/write'
                }
            )
        )
        OR
        (
            @Request[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals {
            4e50c84c-c78e-4e37-b47e-e60ffea0a775 (Service Group Administrator),
            32e6a4ec-6095-4e37-b54b-12aa350ba81f (Service Group Contributor),
            de754d53-652d-4c75-a67f-1e48d8b49c97 (Service Group Reader),
            c914561b-1575-4601-af9c-a1356bf59818 (Azure Resilience Management Drills Administrator),
            e131102b-11a5-4ff4-8508-ed922132b74c (Azure Resilience Management Drills Contributor),
            ff09793b-be48-49f6-ad96-70d32039c0b9 (Azure Resilience Management Drills Operator),
            d2e8fe82-9212-490f-af3e-34bb52d87d3d (Azure Resilience Management Drills Reader),
            481d9636-d9f0-468b-b93d-6056318e6f36 (Azure Resilience Management Recovery Administrator),
            4c7fd853-7345-4453-babd-e9481e9b460b (Azure Resilience Management Recovery Contributor),
            517781b0-5ad4-4418-94d5-f2421834b586 (Azure Resilience Management Recovery Operator),
            8210e6a3-4e4c-4e1a-bd83-ef8bac788a45 (Azure Resilience Management Recovery Reader),
            a2b7cc47-30ec-462f-a2f4-9ac6e1c266af (Azure Resilience Management Goals Administrator),
            3910633d-19d0-4d31-b5e6-4f3101b137b9 (Azure Resilience Management Goals Contributor),
            39ea2c4e-798a-4469-b81d-65dc7c54cbdb (Azure Resilience Management Goals Reader),
            2a31630bc9c748198b504c987cb71337
            }
        )
    )
    AND
    (
        (
            !
            (
                ActionMatches {
                'Microsoft.Authorization/roleAssignments/delete'
                }
            )
        )
        OR
        (
            @Resource[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals {
            4e50c84c-c78e-4e37-b47e-e60ffea0a775 (Service Group Administrator),
            32e6a4ec-6095-4e37-b54b-12aa350ba81f (Service Group Contributor),
            de754d53-652d-4c75-a67f-1e48d8b49c97 (Service Group Reader),
            c914561b-1575-4601-af9c-a1356bf59818 (Azure Resilience Management Drills Administrator),
            e131102b-11a5-4ff4-8508-ed922132b74c (Azure Resilience Management Drills Contributor),
            ff09793b-be48-49f6-ad96-70d32039c0b9 (Azure Resilience Management Drills Operator),
            d2e8fe82-9212-490f-af3e-34bb52d87d3d (Azure Resilience Management Drills Reader),
            481d9636-d9f0-468b-b93d-6056318e6f36 (Azure Resilience Management Recovery Administrator),
            4c7fd853-7345-4453-babd-e9481e9b460b (Azure Resilience Management Recovery Contributor),
            517781b0-5ad4-4418-94d5-f2421834b586 (Azure Resilience Management Recovery Operator),
            8210e6a3-4e4c-4e1a-bd83-ef8bac788a45 (Azure Resilience Management Recovery Reader),
            a2b7cc47-30ec-462f-a2f4-9ac6e1c266af (Azure Resilience Management Goals Administrator),
            3910633d-19d0-4d31-b5e6-4f3101b137b9 (Azure Resilience Management Goals Contributor),
            39ea2c4e-798a-4469-b81d-65dc7c54cbdb (Azure Resilience Management Goals Reader),
            2a31630bc9c748198b504c987cb71337
            }
        )
    )