last sync: 2025-May-01 19:36:20 UTC

Entra Connect Health Service Admin

Azure BuiltIn RBAC Role definition

NameEntra Connect Health Service Admin
Id93629c8c-5d36-4533-85cd-f5bb3338710e
DescriptionCan set up and manage Microsoft Entra Connect Health. Includes agent set up and managing services on the Azure portal
CategoryNone
CreatedOn2025-04-30 16:53:01 UTC
UpdatedOn2025-04-30 16:53:01 UTC
Assignable scopes /providers/Microsoft.ADHybridhealthService
Permissions summary Effective control plane and data plane operations: 56 (unique operations)
•action: 6
•delete: 4
•read: 40
•write: 6

Actions: 56
Resolved control plane operations from Actions: 56
Effective control plane operations: 56
•action: 6
•delete: 4
•read: 40
•write: 6

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 16429

DataActions: 0
Resolved data plane operations: 0
Effective data plane operations: 0

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3385
Actions
Operation Description
Microsoft.ADHybridHealthService/addsservices/actionCreate a new forest for the tenant.
Microsoft.ADHybridHealthService/addsservices/addomainservicemembers/readGets all servers for the specified service name.
Microsoft.ADHybridHealthService/addsservices/alerts/readGets alerts details for the forest like alertid, alert raised date, alert last detected, alert description, last updated, alert level, alert state, alert troubleshooting links etc. .
Microsoft.ADHybridHealthService/addsservices/configuration/readGets Service Configuration for the forest. Example- Forest Name, Functionla Level, Domain Naming master FSMO role, Schema master FSMO role etc.
Microsoft.ADHybridHealthService/addsservices/deleteDeletes a Service and it's servers along with Health data.
Microsoft.ADHybridHealthService/addsservices/dimensions/readGets the domains and sites details for the forest. Example- health status, active alerts, resolved alerts, properties like Domain Functional Level, Forest, Infrastructure Master, PDC, RID master etc.
Microsoft.ADHybridHealthService/addsservices/features/userpreference/readGets the user preference setting for the forest. Example- MetricCounterName like ldapsuccessfulbinds, ntlmauthentications, kerberosauthentications, addsinsightsagentprivatebytes, ldapsearches. Settings for the UI Charts etc.
Microsoft.ADHybridHealthService/addsservices/forestsummary/readGets forest summary for the given forest like forest name, number of domains under this forest, number of sites and sites details etc.
Microsoft.ADHybridHealthService/addsservices/metricmetadata/readGets the list of supported metrics for a given service. For example Extranet Account Lockouts, Total Failed Requests, Outstanding Token Requests (Proxy), Token Requests /sec etc for ADFS service. NTLM Authentications/sec, LDAP Successful Binds/sec, LDAP Bind Time, LDAP Active Threads, Kerberos Authentications/sec, ATQ Threads Total etc for ADDomainService. Run Profile Latency, TCP Connections Established, Insights Agent Private Bytes,Export Statistics to Azure AD for ADSync service.
Microsoft.ADHybridHealthService/addsservices/metrics/groups/readGiven a service, this API gets the metrics information.For example, this API can be used to get information related to: Extranet Account Lockouts, Total Failed Requests, Outstanding Token Requests (Proxy), Token Requests /sec etc for ADFederation service. NTLM Authentications/sec, LDAP Successful Binds/sec, LDAP Bind Time, LDAP Active Threads, Kerberos Authentications/sec, ATQ Threads Total etc for ADDomain Service. Run Profile Latency, TCP Connections Established, Insights Agent Private Bytes,Export Statistics to Azure AD for Sync Service.
Microsoft.ADHybridHealthService/addsservices/premiumcheck/readThis API gets the list of all onboarded ADDomainServices for a premium tenant.
Microsoft.ADHybridHealthService/addsservices/readGets Service details for the specified service name.
Microsoft.ADHybridHealthService/addsservices/replicationdetails/readGets replication details for all the servers for the specified service name.
Microsoft.ADHybridHealthService/addsservices/replicationstatus/readGets the number of domain controllers and their replication errors if any.
Microsoft.ADHybridHealthService/addsservices/replicationsummary/readGets complete domain controller list along with replication details for the given forest.
Microsoft.ADHybridHealthService/addsservices/servicemembers/actionAdd a server instance to the service.
Microsoft.ADHybridHealthService/addsservices/servicemembers/credentials/readDuring server registration of ADDomainService, this api is called to get the credentials for onboarding new servers.
Microsoft.ADHybridHealthService/addsservices/servicemembers/deleteDeletes a server for a given service and tenant.
Microsoft.ADHybridHealthService/addsservices/writeCreates or Updates the ADDomainService instance for the tenant.
Microsoft.ADHybridHealthService/configuration/actionUpdates Tenant Configuration.
Microsoft.ADHybridHealthService/configuration/readReads the Tenant Configuration.
Microsoft.ADHybridHealthService/configuration/writeCreates a Tenant Configuration.
Microsoft.ADHybridHealthService/services/actionUpdates a service instance in the tenant.
Microsoft.ADHybridHealthService/services/alerts/readReads the alerts for a service.
Microsoft.ADHybridHealthService/services/checkservicefeatureavailibility/readGiven a feature name verifies if a service has everything required to use that feature.
Microsoft.ADHybridHealthService/services/deleteDeletes a service instance in the tenant.
Microsoft.ADHybridHealthService/services/exporterrors/readGets the export errors for a given sync service.
Microsoft.ADHybridHealthService/services/exportstatus/readGets the export status for a given service.
Microsoft.ADHybridHealthService/services/feedbacktype/feedback/readGets alerts feedback for a given service and server.
Microsoft.ADHybridHealthService/services/ipAddressAggregates/readReads the bad IPs which attempted to access the service.
Microsoft.ADHybridHealthService/services/ipAddressAggregateSettings/readReads alarm thresholds for bad IPs.
Microsoft.ADHybridHealthService/services/ipAddressAggregateSettings/writeWrites alarm thresholds for bad IPs.
Microsoft.ADHybridHealthService/services/metricmetadata/readGets the list of supported metrics for a given service. For example Extranet Account Lockouts, Total Failed Requests, Outstanding Token Requests (Proxy), Token Requests /sec etc for ADFS service. NTLM Authentications/sec, LDAP Successful Binds/sec, LDAP Bind Time, LDAP Active Threads, Kerberos Authentications/sec, ATQ Threads Total etc for ADDomainService. Run Profile Latency, TCP Connections Established, Insights Agent Private Bytes,Export Statistics to Azure AD for ADSync service.
Microsoft.ADHybridHealthService/services/metrics/groups/average/readGiven a service, this API gets the average for metrics for a given service.For example, this API can be used to get information related to: Extranet Account Lockouts, Total Failed Requests, Outstanding Token Requests (Proxy), Token Requests /sec etc for ADFederation service. NTLM Authentications/sec, LDAP Successful Binds/sec, LDAP Bind Time, LDAP Active Threads, Kerberos Authentications/sec, ATQ Threads Total etc for ADDomain Service. Run Profile Latency, TCP Connections Established, Insights Agent Private Bytes,Export Statistics to Azure AD for Sync Service.
Microsoft.ADHybridHealthService/services/metrics/groups/readGiven a service, this API gets the metrics information.For example, this API can be used to get information related to: Extranet Account Lockouts, Total Failed Requests, Outstanding Token Requests (Proxy), Token Requests /sec etc for ADFederation service. NTLM Authentications/sec, LDAP Successful Binds/sec, LDAP Bind Time, LDAP Active Threads, Kerberos Authentications/sec, ATQ Threads Total etc for ADDomain Service. Run Profile Latency, TCP Connections Established, Insights Agent Private Bytes,Export Statistics to Azure AD for Sync Service.
Microsoft.ADHybridHealthService/services/metrics/groups/sum/readGiven a service, this API gets the aggregated view for metrics for a given service.For example, this API can be used to get information related to: Extranet Account Lockouts, Total Failed Requests, Outstanding Token Requests (Proxy), Token Requests /sec etc for ADFederation service. NTLM Authentications/sec, LDAP Successful Binds/sec, LDAP Bind Time, LDAP Active Threads, Kerberos Authentications/sec, ATQ Threads Total etc for ADDomain Service. Run Profile Latency, TCP Connections Established, Insights Agent Private Bytes,Export Statistics to Azure AD for Sync Service.
Microsoft.ADHybridHealthService/services/monitoringconfiguration/writeAdd or updates monitoring configuration for a service.
Microsoft.ADHybridHealthService/services/monitoringconfigurations/readGets the monitoring configurations for a given service.
Microsoft.ADHybridHealthService/services/monitoringconfigurations/writeAdd or updates monitoring configurations for a service.
Microsoft.ADHybridHealthService/services/premiumcheck/readThis API gets the list of all onboarded services for a premium tenant.
Microsoft.ADHybridHealthService/services/readReads the service instances in the tenant.
Microsoft.ADHybridHealthService/services/reports/blobUris/readGets all Risky IP report URIs for the last 7 days.
Microsoft.ADHybridHealthService/services/reports/details/readGets report of top 50 users with bad password errors from last 7 days
Microsoft.ADHybridHealthService/services/reports/generateBlobUri/actionGenerates Risky IP report and returns a URI pointing to it.
Microsoft.ADHybridHealthService/services/servicemembers/actionCreates or updates a server instance in the service.
Microsoft.ADHybridHealthService/services/servicemembers/alerts/readReads the alerts for a server.
Microsoft.ADHybridHealthService/services/servicemembers/credentials/readDuring server registration, this api is called to get the credentials for onboarding new servers.
Microsoft.ADHybridHealthService/services/servicemembers/datafreshness/readFor a given server, this API gets a list of datatypes that are being uploaded by the servers and the latest time for each upload.
Microsoft.ADHybridHealthService/services/servicemembers/deleteDeletes a server instance in the service.
Microsoft.ADHybridHealthService/services/servicemembers/exportstatus/readGets the Sync Export Error details for a given Sync Service.
Microsoft.ADHybridHealthService/services/servicemembers/metrics/groups/readGiven a service, this API gets the metrics information.For example, this API can be used to get information related to: Extranet Account Lockouts, Total Failed Requests, Outstanding Token Requests (Proxy), Token Requests /sec etc for ADFederation service. NTLM Authentications/sec, LDAP Successful Binds/sec, LDAP Bind Time, LDAP Active Threads, Kerberos Authentications/sec, ATQ Threads Total etc for ADDomain Service. Run Profile Latency, TCP Connections Established, Insights Agent Private Bytes,Export Statistics to Azure AD for Sync Service.
Microsoft.ADHybridHealthService/services/servicemembers/metrics/readGets the list of connectors and run profile names for the given service and service member.
Microsoft.ADHybridHealthService/services/servicemembers/readReads the server instance in the service.
Microsoft.ADHybridHealthService/services/servicemembers/serviceconfiguration/readGets service configuration for a given tenant.
Microsoft.ADHybridHealthService/services/tenantwhitelisting/readGets feature whitelisting status for a given tenant.
Microsoft.ADHybridHealthService/services/writeCreates a service instance in the tenant.
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in
BuiltIn Policy
none
History
Date/Time (UTC ymd) (i) Change Change detail
2025-04-30 19:25:10 add: Role 93629c8c-5d36-4533-85cd-f5bb3338710e
JSON
api-version=2023-07-01-preview
Condition none