Namespace of the resource provider handling policy, resource locks, role definitions and role assignments. Only roles such as Owner and User Access Administrator hold roleAssignments/write.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft.Authorization in context, with comparison tables and the common traps.
Terms in this definition
- Resource provider
Service offering Azure resource types within a namespace, for example Microsoft.Network or Microsoft.Compute. Role actions take the form namespace/resourceType/operation.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- Resource locks
Locks, at ReadOnly or CanNotDelete level, that stop management-plane changes. They place no limits on where resources go or how large they are, and data-plane work such as blob reads and writes carries on regardless.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Full control
Gives every right over protected content, EXTRACT included, plus the ability to alter or strip the encryption. Owners and the Rights Management issuer always hold it.
- User Access Administrator
Granted Microsoft.Authorization/* actions, this Azure role handles role assignments and management locks, yet it can't write tags or manage any other resources. For creating or removing locks, no less-privileged role suffices.