last sync: 2025-Aug-01 17:22:47 UTC

Microsoft Discovery Platform Administrator (Preview)

Azure BuiltIn RBAC Role definition

NameMicrosoft Discovery Platform Administrator (Preview)
Id7a2b6e6c-472e-4b39-8878-a26eb63d75c6
DescriptionGrants full access to manage Microsoft.Discovery resources. This role in preview and subjet to change.
CategoryNone
CreatedOn2025-07-02 15:23:29 UTC
UpdatedOn2025-07-24 17:05:02 UTC
Permissions summary Effective control plane and data plane operations: 120 (unique operations)
•action: 17
•delete: 19
•read: 65
•write: 19

Actions: 13
Resolved control plane operations from Actions: 105
Effective control plane operations: 105
•action: 14
•delete: 15
•read: 59
•write: 17

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 16789

DataActions: 1
Resolved data plane operations: 15
Effective data plane operations: 15
•action: 3
•delete: 4
•read: 6
•write: 2

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3572
Actions
Operation Description
Microsoft.Authorization/*/readwildcarded / no description
Microsoft.Authorization/roleAssignments/delete conditionedDelete a role assignment at the specified scope.
Microsoft.Authorization/roleAssignments/write conditionedCreate a role assignment at the specified scope.
Microsoft.Discovery/*wildcarded / no description
Microsoft.Discovery/checkNameAvailability/actionaction checkNameAvailability
Microsoft.Discovery/locations/operationStatuses/readread operationStatuses
Microsoft.Insights/alertRules/*wildcarded / no description
Microsoft.Network/virtualNetworks/readGet the virtual network definition
Microsoft.Network/virtualNetworks/subnets/join/actionJoins a virtual network. Not Alertable.
Microsoft.Network/virtualNetworks/subnets/readGets a virtual network subnet definition
Microsoft.Resources/deployments/*wildcarded / no description
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups.
Microsoft.Support/*wildcarded / no description
NotActions n/a
DataActions
Operation Description
Microsoft.Discovery/*wildcarded / no description
NotDataActions n/a
Used in
BuiltIn Policy
none
History
Date/Time (UTC ymd) (i) Change Change detail
2025-07-23 17:34:30 change: Actions Actions: 'add Microsoft.Authorization/roleAssignments/write; add Microsoft.Authorization/roleAssignments/delete'
2025-07-15 17:23:58 change: Actions Actions: 'add Microsoft.Network/virtualNetworks/subnets/read; add Microsoft.Network/virtualNetworks/read; add Microsoft.Network/virtualNetworks/subnets/join/action; add Microsoft.Support/*'
2025-07-01 17:22:32 add: Role 7a2b6e6c-472e-4b39-8878-a26eb63d75c6
JSON
api-version=2023-07-01-preview
Condition

    (
        (
            !
            (
                ActionMatches {
                'Microsoft.Authorization/roleAssignments/write'
                }
            )
        )
        OR
        (
            @Request[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals {
            4d97b98b-1d4f-4787-a291-c67834d212e7 (Network Contributor),
            f1a07417-d97a-45cb-824c-7a7467783830 (Managed Identity Operator)
            }
        )
    )
    AND
    (
        (
            !
            (
                ActionMatches {
                'Microsoft.Authorization/roleAssignments/delete'
                }
            )
        )
        OR
        (
            @Resource[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals {
            4d97b98b-1d4f-4787-a291-c67834d212e7 (Network Contributor),
            f1a07417-d97a-45cb-824c-7a7467783830 (Managed Identity Operator)
            }
        )
    )