A set of permissions, for example read, write and delete, that is either built in (Owner, Contributor, Reader and others) or custom. People normally just call it a role.
Also called role.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Role definition in context, with comparison tables and the common traps.
Terms in this definition
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
- Full control
Gives every right over protected content, EXTRACT included, plus the ability to alter or strip the encryption. Owners and the Rights Management issuer always hold it.
- Contributor
Built-in Azure role with full management of resources, except that it can't give access to anyone.
- Reader
Built-in Azure role for viewing resources only: it cannot modify or use them, for example by joining or associating them, and gives no keys or data access.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
Related terms
- AssignableScopes
Property of a role definition stating at which management groups, subscriptions, resource groups or resources a custom role may be assigned.
- DataActions
Section of a role definition listing data-plane operations, such as reading blobs or logging in to a VM; putting these operations under Actions instead has no effect.
- Get-AzRoleDefinition
An Az cmdlet for retrieving a role definition. Piping its output into
ConvertTo-Jsonproduces a starting file for building a custom role. - NotActions
List in a role definition whose entries are removed from Actions, such as
Microsoft.Authorization/*in the Contributor pattern. It is not a deny, so a different role can still grant those operations. - Role assignment
Gives access in Azure RBAC by binding three things together: who (a security principal), what (a role definition) and where (a scope).
- Role definition Actions
In a role definition, the list of control-plane operations that are permitted, for example
Microsoft.Storage/storageAccounts/read. Wildcards like*may be used.