Azure Add App Role Assignment To Service Principal
Grants a resource application role to a client service principal.
All events with tag Azure.
Grants a resource application role to a client service principal.
Creates an application registration in Microsoft Entra ID.
Records completed creation of PIM role eligibility.
Adds an external workload trust to a Microsoft Entra application registration.
Adds a principal to a Microsoft Entra directory role.
Adds an owner to a Microsoft Entra application registration.
Adds an owner to a Microsoft Entra group.
Creates a custom Azure resource RBAC role definition.
Creates a tenant-local service principal in Microsoft Entra ID.
Creates a user object in Microsoft Entra ID.
Records a domain becoming verified in a Microsoft Entra tenant.
Records an administrator registering user authentication information.
Records consent to an application’s requested permissions.
Requests a server-side copy of an Azure blob.
Records removal of a user’s per-user MFA requirement.
Invites an external identity to collaborate in a Microsoft Entra tenant.
Retrieves access keys for an Azure App Configuration store.
Grants an Entra Global Administrator Azure User Access Administrator at root scope.
Deletes an Azure management lock.
Deletes an Azure RBAC role assignment.
Creates or updates an Azure RBAC role assignment, granting a principal specific permissions on a resource or scope.
Reads Azure Automation credential-asset metadata.
Creates an Azure Automation runbook job.
Creates or updates an Azure Automation runbook resource.
Generates a URI for an Azure Automation webhook.
Creates or updates an Azure Automation runbook webhook.
Retrieves shared keys for an Azure Batch account.
Requests temporary access to an Azure managed disk.
Requests temporary access to an Azure managed-disk snapshot.
Creates or updates an Azure SSH public-key resource.
Requests deletion of an Azure virtual machine.
Creates or updates an extension on an Azure virtual machine.
Requests script execution through Azure VM Action Run Command.
Creates or updates an Azure virtual machine resource.
Retrieves the shared admin credentials of an Azure Container Registry.
Requests local cluster-admin kubeconfig credentials for an AKS cluster.
Retrieves the clusterUser kubeconfig for an AKS cluster.
Requests execution of a command through AKS Run Command.
Updates membership of an Entra group that is not role-assignable.
Adds or updates credentials on an Entra service principal.
Deletes an Event Hub entity within an Azure Event Hubs namespace.
Requests removal of an extension from an Azure Arc-enabled server.
Deletes an Azure Monitor activity log alert rule.
Deletes an Azure Monitor diagnostic setting and its configured export routes.
Deletes an Azure Monitor metric alert rule.
Changes access-policy entries for an Azure Key Vault.
Reads a Key Vault certificate’s public certificate and metadata.
Deletes an Azure Key Vault resource, subject to recovery and purge controls.
Reads a Key Vault key’s public material and metadata.
Deletes a named Key Vault secret and all its versions.
Reads the value of an Azure Key Vault secret.
Authorizes attaching an existing user-assigned managed identity to a resource.
Deletes an Azure network security group after its resource associations are removed.
Creates or updates a rule in an Azure network security group.
Deletes an Azure Network Watcher flow-log configuration.
Creates or updates one side of an Azure virtual network peering.
Deletes an Azure Log Analytics workspace, with optional permanent deletion.
Retrieves primary and secondary shared keys for a Log Analytics workspace.
Requests removal of protection and backup data for an Azure Backup protected item.
Creates or updates a Defender for Cloud alert suppression rule.
Updates the legacy Defender for Cloud agent auto-provisioning setting.
Changes a Microsoft Defender for Cloud plan configuration at a supported scope.
Deletes a Microsoft.Security security solution resource.
Requests a connection to an Azure VM serial console.
Retrieves shared keys and connection strings for a Service Bus namespace authorization rule.
Deletes an Azure SQL Database while recovery depends on retained backups.
Requests export of Azure SQL Database schema and data to a BACPAC in Blob Storage.
Deletes an Azure Blob Storage container through the management plane.
Deletes an Azure Storage account and makes its services unavailable.
Retrieves an Azure Storage account’s shared access keys.
Regenerates a selected Azure Storage account access key.
Retrieves Azure Functions host, master, and system keys.
Records an administrative password reset for a Microsoft Entra user.
Disables selected legacy Azure Storage Analytics logging categories.
Updates an existing Microsoft Entra Conditional Access policy.
Updates an Entra Conditional Access named network/location definition.
Updates a custom Azure resource RBAC role definition.
Records changes to a user’s registered Entra authentication methods.
Updates Azure Key Vault properties through a management-plane write.