role_assignments
Creates, updates, deletes, gets or lists a role_assignments resource.
Overview
| Name | role_assignments |
| Type | Resource |
| Id | azure.authorization.role_assignments |
Fields
The following fields are returned by SELECT queries:
- list_for_resource
- get
- list_for_resource_group
- list_for_scope
- list_for_subscription
- get_by_id
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
condition | string | The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'. |
conditionVersion | string | Version of the condition. Currently the only accepted value is '2.0'. |
createdBy | string | Id of the user who created the assignment. |
createdOn | string (date-time) | Time it was created. |
delegatedManagedIdentityResourceId | string | Id of the delegated managed identity resource. |
description | string | Description of role assignment. |
principalId | string | The principal ID. Required. |
principalType | string | The principal type of the assigned principal ID. Known values are: "User", "Group", "ServicePrincipal", "ForeignGroup", and "Device". (User, Group, ServicePrincipal, ForeignGroup, Device) |
roleDefinitionId | string | The role definition ID. Required. |
scope | string | The role assignment scope. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
updatedBy | string | Id of the user who updated the assignment. |
updatedOn | string (date-time) | Time it was updated. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
condition | string | The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'. |
conditionVersion | string | Version of the condition. Currently the only accepted value is '2.0'. |
createdBy | string | Id of the user who created the assignment. |
createdOn | string (date-time) | Time it was created. |
delegatedManagedIdentityResourceId | string | Id of the delegated managed identity resource. |
description | string | Description of role assignment. |
principalId | string | The principal ID. Required. |
principalType | string | The principal type of the assigned principal ID. Known values are: "User", "Group", "ServicePrincipal", "ForeignGroup", and "Device". (User, Group, ServicePrincipal, ForeignGroup, Device) |
roleDefinitionId | string | The role definition ID. Required. |
scope | string | The role assignment scope. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
updatedBy | string | Id of the user who updated the assignment. |
updatedOn | string (date-time) | Time it was updated. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
condition | string | The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'. |
conditionVersion | string | Version of the condition. Currently the only accepted value is '2.0'. |
createdBy | string | Id of the user who created the assignment. |
createdOn | string (date-time) | Time it was created. |
delegatedManagedIdentityResourceId | string | Id of the delegated managed identity resource. |
description | string | Description of role assignment. |
principalId | string | The principal ID. Required. |
principalType | string | The principal type of the assigned principal ID. Known values are: "User", "Group", "ServicePrincipal", "ForeignGroup", and "Device". (User, Group, ServicePrincipal, ForeignGroup, Device) |
roleDefinitionId | string | The role definition ID. Required. |
scope | string | The role assignment scope. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
updatedBy | string | Id of the user who updated the assignment. |
updatedOn | string (date-time) | Time it was updated. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
condition | string | The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'. |
conditionVersion | string | Version of the condition. Currently the only accepted value is '2.0'. |
createdBy | string | Id of the user who created the assignment. |
createdOn | string (date-time) | Time it was created. |
delegatedManagedIdentityResourceId | string | Id of the delegated managed identity resource. |
description | string | Description of role assignment. |
principalId | string | The principal ID. Required. |
principalType | string | The principal type of the assigned principal ID. Known values are: "User", "Group", "ServicePrincipal", "ForeignGroup", and "Device". (User, Group, ServicePrincipal, ForeignGroup, Device) |
roleDefinitionId | string | The role definition ID. Required. |
scope | string | The role assignment scope. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
updatedBy | string | Id of the user who updated the assignment. |
updatedOn | string (date-time) | Time it was updated. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
condition | string | The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'. |
conditionVersion | string | Version of the condition. Currently the only accepted value is '2.0'. |
createdBy | string | Id of the user who created the assignment. |
createdOn | string (date-time) | Time it was created. |
delegatedManagedIdentityResourceId | string | Id of the delegated managed identity resource. |
description | string | Description of role assignment. |
principalId | string | The principal ID. Required. |
principalType | string | The principal type of the assigned principal ID. Known values are: "User", "Group", "ServicePrincipal", "ForeignGroup", and "Device". (User, Group, ServicePrincipal, ForeignGroup, Device) |
roleDefinitionId | string | The role definition ID. Required. |
scope | string | The role assignment scope. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
updatedBy | string | Id of the user who updated the assignment. |
updatedOn | string (date-time) | Time it was updated. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
condition | string | The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'. |
conditionVersion | string | Version of the condition. Currently the only accepted value is '2.0'. |
createdBy | string | Id of the user who created the assignment. |
createdOn | string (date-time) | Time it was created. |
delegatedManagedIdentityResourceId | string | Id of the delegated managed identity resource. |
description | string | Description of role assignment. |
principalId | string | The principal ID. Required. |
principalType | string | The principal type of the assigned principal ID. Known values are: "User", "Group", "ServicePrincipal", "ForeignGroup", and "Device". (User, Group, ServicePrincipal, ForeignGroup, Device) |
roleDefinitionId | string | The role definition ID. Required. |
scope | string | The role assignment scope. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
updatedBy | string | Id of the user who updated the assignment. |
updatedOn | string (date-time) | Time it was updated. |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
list_for_resource | select | resource_group_name, resource_provider_namespace, resource_type, resource_name, subscription_id | $filter, tenantId | List all role assignments that apply to a resource. |
get | select | scope, role_assignment_name | tenantId | Get a role assignment by scope and name. |
list_for_resource_group | select | resource_group_name, subscription_id | $filter, tenantId | List all role assignments that apply to a resource group. |
list_for_scope | select | scope | $filter, tenantId, $skipToken | List all role assignments that apply to a scope. |
list_for_subscription | select | subscription_id | $filter, tenantId | List all role assignments that apply to a subscription. |
get_by_id | select | role_assignment_id | tenantId | Get a role assignment by ID. |
create | insert | scope, role_assignment_name, properties | Create or update a role assignment by scope and name. | |
create_by_id | insert | role_assignment_id, properties | Create or update a role assignment by ID. | |
delete | delete | scope, role_assignment_name | tenantId | Delete a role assignment by scope and name. |
delete_by_id | delete | role_assignment_id | tenantId | Delete a role assignment by ID. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
resource_group_name | string | The name of the resource group. The name is case insensitive. Required. |
resource_name | string | The name of the resource to get role assignments for. Required. |
resource_provider_namespace | string | The namespace of the resource provider. Required. |
resource_type | string | The resource type of the resource. Required. |
role_assignment_id | string | The fully qualified ID of the role assignment including scope, resource name, and resource type. Format: /{scope}/providers/Microsoft.Authorization/roleAssignments/{roleAssignmentName}. Example: /subscriptions//resourcegroups//providers/Microsoft.Authorization/roleAssignments/. Required. |
role_assignment_name | string | The name of the role assignment. It can be any valid GUID. Required. |
scope | string | The fully qualified Azure Resource manager identifier of the resource. Required. |
subscription_id | string | |
$filter | string | The filter to apply on the operation. Use $filter=atScope() to return all role assignments at or above the scope. Use $filter=principalId eq {id} to return all role assignments at, above or below the scope for the specified principal. Default value is None. |
$skipToken | string | The skipToken to apply on the operation. Use $skipToken={skiptoken} to return paged role assignments following the skipToken passed. Only supported on provider level calls. Default value is None. |
tenantId | string | Tenant ID for cross-tenant request. Default value is None. |
SELECT examples
- list_for_resource
- get
- list_for_resource_group
- list_for_scope
- list_for_subscription
- get_by_id
List all role assignments that apply to a resource.
SELECT
id,
name,
condition,
conditionVersion,
createdBy,
createdOn,
delegatedManagedIdentityResourceId,
description,
principalId,
principalType,
roleDefinitionId,
scope,
systemData,
type,
updatedBy,
updatedOn
FROM azure.authorization.role_assignments
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND resource_provider_namespace = '{{ resource_provider_namespace }}' -- required
AND resource_type = '{{ resource_type }}' -- required
AND resource_name = '{{ resource_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
AND $filter = '{{ $filter }}'
AND tenantId = '{{ tenantId }}'
;
Get a role assignment by scope and name.
SELECT
id,
name,
condition,
conditionVersion,
createdBy,
createdOn,
delegatedManagedIdentityResourceId,
description,
principalId,
principalType,
roleDefinitionId,
scope,
systemData,
type,
updatedBy,
updatedOn
FROM azure.authorization.role_assignments
WHERE scope = '{{ scope }}' -- required
AND role_assignment_name = '{{ role_assignment_name }}' -- required
AND tenantId = '{{ tenantId }}'
;
List all role assignments that apply to a resource group.
SELECT
id,
name,
condition,
conditionVersion,
createdBy,
createdOn,
delegatedManagedIdentityResourceId,
description,
principalId,
principalType,
roleDefinitionId,
scope,
systemData,
type,
updatedBy,
updatedOn
FROM azure.authorization.role_assignments
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
AND $filter = '{{ $filter }}'
AND tenantId = '{{ tenantId }}'
;
List all role assignments that apply to a scope.
SELECT
id,
name,
condition,
conditionVersion,
createdBy,
createdOn,
delegatedManagedIdentityResourceId,
description,
principalId,
principalType,
roleDefinitionId,
scope,
systemData,
type,
updatedBy,
updatedOn
FROM azure.authorization.role_assignments
WHERE scope = '{{ scope }}' -- required
AND $filter = '{{ $filter }}'
AND tenantId = '{{ tenantId }}'
AND $skipToken = '{{ $skipToken }}'
;
List all role assignments that apply to a subscription.
SELECT
id,
name,
condition,
conditionVersion,
createdBy,
createdOn,
delegatedManagedIdentityResourceId,
description,
principalId,
principalType,
roleDefinitionId,
scope,
systemData,
type,
updatedBy,
updatedOn
FROM azure.authorization.role_assignments
WHERE subscription_id = '{{ subscription_id }}' -- required
AND $filter = '{{ $filter }}'
AND tenantId = '{{ tenantId }}'
;
Get a role assignment by ID.
SELECT
id,
name,
condition,
conditionVersion,
createdBy,
createdOn,
delegatedManagedIdentityResourceId,
description,
principalId,
principalType,
roleDefinitionId,
scope,
systemData,
type,
updatedBy,
updatedOn
FROM azure.authorization.role_assignments
WHERE role_assignment_id = '{{ role_assignment_id }}' -- required
AND tenantId = '{{ tenantId }}'
;
INSERT examples
- create
- create_by_id
- Manifest
Create or update a role assignment by scope and name.
INSERT INTO azure.authorization.role_assignments (
properties,
scope,
role_assignment_name
)
SELECT
'{{ properties }}' /* required */,
'{{ scope }}',
'{{ role_assignment_name }}'
RETURNING
id,
name,
properties,
systemData,
type
;
Create or update a role assignment by ID.
INSERT INTO azure.authorization.role_assignments (
properties,
role_assignment_id
)
SELECT
'{{ properties }}' /* required */,
'{{ role_assignment_id }}'
RETURNING
id,
name,
properties,
systemData,
type
;
# Description fields are for documentation purposes
- name: role_assignments
props:
- name: scope
value: "{{ scope }}"
description: Required parameter for the role_assignments resource.
- name: role_assignment_name
value: "{{ role_assignment_name }}"
description: Required parameter for the role_assignments resource.
- name: role_assignment_id
value: "{{ role_assignment_id }}"
description: Required parameter for the role_assignments resource.
- name: properties
description: |
Role assignment properties. Required.
value:
scope: "{{ scope }}"
roleDefinitionId: "{{ roleDefinitionId }}"
principalId: "{{ principalId }}"
principalType: "{{ principalType }}"
description: "{{ description }}"
condition: "{{ condition }}"
conditionVersion: "{{ conditionVersion }}"
createdOn: "{{ createdOn }}"
updatedOn: "{{ updatedOn }}"
createdBy: "{{ createdBy }}"
updatedBy: "{{ updatedBy }}"
delegatedManagedIdentityResourceId: "{{ delegatedManagedIdentityResourceId }}"
DELETE examples
- delete
- delete_by_id
Delete a role assignment by scope and name.
DELETE FROM azure.authorization.role_assignments
WHERE scope = '{{ scope }}' --required
AND role_assignment_name = '{{ role_assignment_name }}' --required
AND tenantId = '{{ tenantId }}'
;
Delete a role assignment by ID.
DELETE FROM azure.authorization.role_assignments
WHERE role_assignment_id = '{{ role_assignment_id }}' --required
AND tenantId = '{{ tenantId }}'
;