permissions
  • General
  • Dashboard
  • Reference Usage
  • Built-in Roles
  • Policy Evaluator
  • Cloud Providers
  • AWS
  • Azure
  • Google Cloud
  • Reference

Type / to search...



  1. Reference

Permissions Reference for

IAM Actions defined by

You can specify the following actions in the Actions element of an Azure role definition.

IAM Actions

-

API Methods

-

Method Short Description Used By Access Level Description Origins
API Methods defined by

You can use the following methods in the Azure CLI, SDKs or API.

IAM Actions

-

API Methods

-

Operation ID Description IAM Actions REST URI Versions
Download the permissions in JSON format.

Consume the above permissions with your own tooling.

  1. General
  2. Dashboard

Dashboard

Actions

Number of known actions within the Azure RBAC service.

API Methods

Number of known API methods within all of Azure.

Built-in Roles

Number of built-in roles provided by Azure.

  1. General
  2. Reference Usage

Reference Usage

About azure.permissions.cloud

The azure.permissions.cloud website uses a variety of information gathered within the IAM Dataset and exposes that information in a clean, easy-to-read format.

azure.permissions.cloud was built in order to provide an alternate, community-driven source of truth for Azure identity. If you would like to contribute to or suggest a feature for this website, please raise it in the azure.permissions.cloud repo. If you have found a data issue with the IAM permissions or API methods, please raise it in the IAM Dataset repo.

The website can be navigated using the left sidebar or by quickly looking up a specific managed policy, permission or API method in the top search bar.


Using the Dashboard

The dashboard has a small selection of statistics about the global state of permissions and API methods.


Using Built-in Roles

The built-in roles section lists all known Azure built-in roles with the ability to view individual roles in-depth. Additional analysis is presented about the effective permissions the policy provides.

The following table represents the attributes available on either a built-in role or an effective permissions within it:

Tag Description
external actions A built-in role tag indicating that the built-in role contains actions that are external to the code Azure ecosystem, typically for third parties.
unknown actions A built-in role tag indicating that the built-in role contains an action that is not documented in the official provider operations reference.
undocumented actions A built-in role tag that indicates the presence of undocumented actions within the policy.
malformed A built-in role tag that indicates the presence of a malformed statement within the policy.
deprecated A built-in role tag that indicates the policy is deprecated.

Using IAM Permissions

IAM Permissions are available on all service pages. Each IAM permission details its own identifier, short and long descriptions, access level, as well as permitted origins where available.


Using API Methods

API Methods are available on all service pages. Each API Method details its own identifier, short and long descriptions, as well as permitted origins where available.

  1. General
  2. Built-in Roles

Built-in Roles

Azure Built-in Roles

Below is a list of Azure Built-in Roles.

Active Built-in Roles

-

Deprecated Built-in Roles

-

Name Description
  1. General
  2. Built-in Roles

Raw Policy

Below is the raw built-in role policy.

Effective Actions

Below is a breakdown of the effective actions for the built-in role.

Action Based On Origins
  1. General
  2. Policy Evaluator

Policy Evaluator

Custom Policy

Enter your custom role JSON in the box below.

Effective Actions

Below is a breakdown of the effective actions for the policy.

Action Based On Origins
API Request Location