管理和治理的 Azure 权限

本文列出了管理和治理类别中 Azure 资源提供程序的权限。 你可以在自己的 Azure 自定义角色中使用这些权限,以针对 Azure 中的资源提供精细访问控制。 权限字符串采用以下格式:{Company}.{ProviderName}/{resourceType}/{action}

Microsoft.Advisor

个性化 Azure 最佳做法推荐引擎。

Azure 服务:Azure 顾问

操作 说明
Microsoft.Advisor/generateRecommendations/action 获取“生成建议”状态
Microsoft.Advisor/register/action 注册 Microsoft 顾问的订阅
Microsoft.Advisor/unregister/action 取消注册 Microsoft 顾问的订阅
Microsoft.Advisor/advisorScore/read 获取给定订阅的评分数据
Microsoft.Advisor/assessments/read 读取评估
Microsoft.Advisor/assessments/write 写入评估
Microsoft.Advisor/assessmentTypes/read 读取 assessmentTypes
Microsoft.Advisor/configurations/read 获取配置
Microsoft.Advisor/configurations/write 创建/更新配置
Microsoft.Advisor/generateRecommendations/read 获取“生成建议”状态
Microsoft.Advisor/metadata/read 获取元数据
Microsoft.Advisor/operations/read 获取 Microsoft 顾问的操作
Microsoft.Advisor/recommendations/read 读取建议
Microsoft.Advisor/recommendations/write 写入建议
Microsoft.Advisor/recommendations/available/action Microsoft 顾问中提供了新建议
Microsoft.Advisor/recommendations/suppressions/read 获取禁止显示
Microsoft.Advisor/recommendations/suppressions/write 创建/更新禁止显示
Microsoft.Advisor/recommendations/suppressions/delete 删除禁止显示
Microsoft.Advisor/resiliencyReviews/read 读取 resiliencyReviews
Microsoft.Advisor/suppressions/read 获取禁止显示
Microsoft.Advisor/suppressions/write 创建/更新禁止显示
Microsoft.Advisor/suppressions/delete 删除禁止显示
Microsoft.Advisor/triageRecommendations/read 读取 triageRecommendations
Microsoft.Advisor/triageRecommendations/approve/action 批准 triageRecommendations
Microsoft.Advisor/triageRecommendations/reject/action 拒绝 triageRecommendations
Microsoft.Advisor/triageRecommendations/reset/action 重置 triageRecommendations
Microsoft.Advisor/workloads/read 读取工作负荷

Microsoft.Authorization

Azure 服务:Azure PolicyAzure RBACAzure 资源管理器

操作 说明
Microsoft.Authorization/elevateAccess/action 向调用方授予租户范围的“用户访问管理员”访问权限
Microsoft.Authorization/classicAdministrators/read 读取订阅的管理员。 如果在自定义角色中用作 NotAction,则不起作用。
Microsoft.Authorization/classicAdministrators/write 在订阅中添加或修改管理员。
Microsoft.Authorization/classicAdministrators/delete 从订阅中删除管理员。
Microsoft.Authorization/classicAdministrators/operationstatuses/read 获取订阅的管理员操作状态。
Microsoft.Authorization/denyAssignments/read 获取拒绝分配的相关信息。
Microsoft.Authorization/denyAssignments/write 在指定范围处创建拒绝分配。
Microsoft.Authorization/denyAssignments/delete 在指定范围处删除拒绝分配。
Microsoft.Authorization/diagnosticSettings/read 阅读有关诊断设置的信息
Microsoft.Authorization/diagnosticSettings/write 创建或更新诊断设置的信息
Microsoft.Authorization/diagnosticSettings/delete 删除诊断设置
Microsoft.Authorization/diagnosticSettingsCategories/read 获取有关诊断设置类别的信息
Microsoft.Authorization/locks/read 获取指定范围的锁。
Microsoft.Authorization/locks/write 添加指定范围的锁。
Microsoft.Authorization/locks/delete 删除指定范围的锁。
Microsoft.Authorization/operations/read 获取操作列表
Microsoft.Authorization/permissions/read 列出调用方在给定范围拥有的所有权限。
Microsoft.Authorization/policies/audit/action 因 Azure 策略评估影响程度为“audit”而执行的操作
Microsoft.Authorization/policies/auditIfNotExists/action 因 Azure 策略评估影响程度为“auditIfNotExists”而执行的操作
Microsoft.Authorization/policies/deny/action 因 Azure 策略评估影响程度为“deny”而执行的操作
Microsoft.Authorization/policies/deployIfNotExists/action 因 Azure 策略评估影响程度为“deployIfNotExists”而执行的操作
Microsoft.Authorization/policyAssignments/read 获取有关策略分配的信息。
Microsoft.Authorization/policyAssignments/write 创建指定范围的策略分配。
Microsoft.Authorization/policyAssignments/delete 删除指定范围的策略分配。
Microsoft.Authorization/policyAssignments/exempt/action 豁免指定范围内的策略分配。
Microsoft.Authorization/policyAssignments/privateLinkAssociations/read 获取有关专用链接关联的信息。
Microsoft.Authorization/policyAssignments/privateLinkAssociations/write 创建或更新专用链接关联。
Microsoft.Authorization/policyAssignments/privateLinkAssociations/delete 删除专用链接关联。
Microsoft.Authorization/policyAssignments/resourceManagementPrivateLinks/read 获取有关资源管理专用链接的信息。
Microsoft.Authorization/policyAssignments/resourceManagementPrivateLinks/write 创建或更新资源管理专用链接。
Microsoft.Authorization/policyAssignments/resourceManagementPrivateLinks/delete 删除资源管理专用链接。
Microsoft.Authorization/policyAssignments/resourceManagementPrivateLinks/privateEndpointConnectionProxies/read 获取有关专用终结点连接代理的信息。
Microsoft.Authorization/policyAssignments/resourceManagementPrivateLinks/privateEndpointConnectionProxies/write 创建或更新专用终结点连接代理。
Microsoft.Authorization/policyAssignments/resourceManagementPrivateLinks/privateEndpointConnectionProxies/delete 删除专用终结点连接代理。
Microsoft.Authorization/policyAssignments/resourceManagementPrivateLinks/privateEndpointConnectionProxies/validate/action 验证专用终结点连接代理。
Microsoft.Authorization/policyAssignments/resourceManagementPrivateLinks/privateEndpointConnections/read 获取有关专用终结点连接的信息。
Microsoft.Authorization/policyAssignments/resourceManagementPrivateLinks/privateEndpointConnections/write 创建或更新专用终结点连接。
Microsoft.Authorization/policyAssignments/resourceManagementPrivateLinks/privateEndpointConnections/delete 删除专用终结点连接。
Microsoft.Authorization/policyDefinitions/read 获取有关策略定义的信息。
Microsoft.Authorization/policyDefinitions/write 创建自定义策略定义。
Microsoft.Authorization/policyDefinitions/delete 删除策略定义。
Microsoft.Authorization/policyExemptions/read 获取有关策略豁免的信息。
Microsoft.Authorization/policyExemptions/write 创建指定范围内的策略豁免。
Microsoft.Authorization/policyExemptions/delete 删除指定范围内的策略豁免。
Microsoft.Authorization/policySetDefinitions/read 获取有关策略集定义的信息。
Microsoft.Authorization/policySetDefinitions/write 创建自定义策略集定义。
Microsoft.Authorization/policySetDefinitions/delete 删除策略集定义。
Microsoft.Authorization/providerOperations/read 获取可在角色定义中使用的所有资源提供程序的操作。
Microsoft.Authorization/roleAssignments/read 获取有关角色分配的信息。
Microsoft.Authorization/roleAssignments/write 创建指定范围的角色分配。
Microsoft.Authorization/roleAssignments/delete 删除指定范围的角色分配。
Microsoft.Authorization/roleAssignmentScheduleInstances/read 获取给定范围内的角色分配计划实例。
Microsoft.Authorization/roleAssignmentScheduleRequests/read 获取给定范围内的角色分配计划请求。
Microsoft.Authorization/roleAssignmentScheduleRequests/write 创建给定范围内的角色分配计划请求。
Microsoft.Authorization/roleAssignmentScheduleRequests/cancel/action 取消挂起的角色分配计划请求。
Microsoft.Authorization/roleAssignmentSchedules/read 获取给定范围内的角色分配计划。
Microsoft.Authorization/roleDefinitions/read 获取有关角色定义的信息。
Microsoft.Authorization/roleDefinitions/write 使用指定的权限和可分配的范围创建或更新自定义角色定义。
Microsoft.Authorization/roleDefinitions/delete 删除指定的自定义角色定义。
Microsoft.Authorization/roleEligibilityScheduleInstances/read 获取给定范围内的角色资格计划实例。
Microsoft.Authorization/roleEligibilityScheduleRequests/read 获取给定范围内的角色资格计划请求。
Microsoft.Authorization/roleEligibilityScheduleRequests/write 在给定范围内创建角色资格计划请求。
Microsoft.Authorization/roleEligibilityScheduleRequests/cancel/action 取消挂起的角色资格计划请求。
Microsoft.Authorization/roleEligibilitySchedules/read 获取给定范围内的角色资格计划。
Microsoft.Authorization/roleManagementPolicies/read 获取角色管理策略
Microsoft.Authorization/roleManagementPolicies/write 更新角色管理策略
Microsoft.Authorization/roleManagementPolicyAssignments/read 获取角色管理策略分配

Microsoft.Automation

使用流程自动化来简化云管理。

Azure 服务:自动化

操作 说明
Microsoft.Automation/register/action 将订阅注册到 Azure Automation
Microsoft.Automation/automationAccounts/convertGraphRunbookContent/action 将 Graph Runbook 内容转换为其原始序列化格式,反之亦然
Microsoft.Automation/automationAccounts/webhooks/action 生成 Azure 自动化 Webhook 的 URI
Microsoft.Automation/automationAccounts/read 获取 Azure 自动化帐户
Microsoft.Automation/automationAccounts/write 创建或更新 Azure 自动化帐户
Microsoft.Automation/automationAccounts/listKeys/action 读取自动化帐户的键
Microsoft.Automation/automationAccounts/delete 删除 Azure 自动化帐户
Microsoft.Automation/automationAccounts/agentRegistrationInformation/read 读取 Azure Automation DSC 的注册信息
Microsoft.Automation/automationAccounts/agentRegistrationInformation/regenerateKey/action 写入重新生成 Azure Automation DSC 密钥的请求
Microsoft.Automation/automationAccounts/certificates/getCount/action 读取证书的计数
Microsoft.Automation/automationAccounts/certificates/read 获取 Azure 自动化证书资产
Microsoft.Automation/automationAccounts/certificates/write 创建或更新 Azure 自动化证书资产
Microsoft.Automation/automationAccounts/certificates/delete 删除 Azure 自动化证书资产
Microsoft.Automation/automationAccounts/compilationjobs/write 写入 Azure Automation DSC 的编译
Microsoft.Automation/automationAccounts/compilationjobs/read 读取 Azure Automation DSC 的编译
Microsoft.Automation/automationAccounts/configurations/read 获取 Azure 自动化 DSC 的内容
Microsoft.Automation/automationAccounts/configurations/getCount/action 读取 Azure Automation DSC 的内容计数
Microsoft.Automation/automationAccounts/configurations/write 写入 Azure Automation DSC 的内容
Microsoft.Automation/automationAccounts/configurations/delete 删除 Azure Automation DSC 的内容
Microsoft.Automation/automationAccounts/configurations/content/read 读取配置媒体内容
Microsoft.Automation/automationAccounts/connections/read 获取 Azure 自动化连接资产
Microsoft.Automation/automationAccounts/connections/getCount/action 读取连接的计数
Microsoft.Automation/automationAccounts/connections/write 创建或更新 Azure 自动化连接资产
Microsoft.Automation/automationAccounts/connections/delete 删除 Azure 自动化连接资产
Microsoft.Automation/automationAccounts/connectionTypes/read 获取 Azure 自动化连接类型资产
Microsoft.Automation/automationAccounts/connectionTypes/write 创建 Azure 自动化连接类型资产
Microsoft.Automation/automationAccounts/connectionTypes/delete 删除 Azure 自动化连接类型资产
Microsoft.Automation/automationAccounts/credentials/read 获取 Azure 自动化凭据资产
Microsoft.Automation/automationAccounts/credentials/getCount/action 读取凭据的计数
Microsoft.Automation/automationAccounts/credentials/write 创建或更新 Azure 自动化凭据资产
Microsoft.Automation/automationAccounts/credentials/delete 删除 Azure 自动化凭据资产
Microsoft.Automation/automationAccounts/diagnosticSettings/read 获取资源的诊断设置
Microsoft.Automation/automationAccounts/diagnosticSettings/write 设置资源的诊断设置
Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/read 读取混合 Runbook 辅助角色组
Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/write 创建混合 Runbook 辅助角色组
Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/delete 删除混合 Runbook 辅助角色组
Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/hybridRunbookWorkers/read 读取混合 Runbook 辅助角色
Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/hybridRunbookWorkers/write 创建混合 Runbook 辅助角色
Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/hybridRunbookWorkers/move/action 将混合 Runbook 辅助角色从一个辅助角色组移到另一个组
Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/hybridRunbookWorkers/delete 删除混合 Runbook 辅助角色
Microsoft.Automation/automationAccounts/jobs/runbookContent/action 执行作业时获取 Azure 自动化 Runbook 的内容
Microsoft.Automation/automationAccounts/jobs/read 获取 Azure 自动化作业
Microsoft.Automation/automationAccounts/jobs/write 创建 Azure 自动化作业
Microsoft.Automation/automationAccounts/jobs/stop/action 停止 Azure 自动化作业
Microsoft.Automation/automationAccounts/jobs/suspend/action 暂停 Azure 自动化作业
Microsoft.Automation/automationAccounts/jobs/resume/action 恢复 Azure 自动化作业
Microsoft.Automation/automationAccounts/jobs/output/read 获取作业的输出
Microsoft.Automation/automationAccounts/jobs/streams/read 获取 Azure 自动化作业流
Microsoft.Automation/automationAccounts/jobSchedules/read 获取 Azure 自动化作业计划
Microsoft.Automation/automationAccounts/jobSchedules/write 创建 Azure 自动化作业计划
Microsoft.Automation/automationAccounts/jobSchedules/delete 删除 Azure 自动化作业计划
Microsoft.Automation/automationAccounts/linkedWorkspace/read 获取链接到自动化帐户的工作区
Microsoft.Automation/automationAccounts/logDefinitions/read 获取自动化帐户的可用日志
Microsoft.Automation/automationAccounts/modules/read 获取 Azure 自动化 Powershell 模块
Microsoft.Automation/automationAccounts/modules/getCount/action 获取自动化帐户中的 Powershell 模块的计数
Microsoft.Automation/automationAccounts/modules/write 创建或更新 Azure 自动化 Powershell 模块
Microsoft.Automation/automationAccounts/modules/delete 删除 Azure 自动化 Powershell 模块
Microsoft.Automation/automationAccounts/modules/activities/read 获取 Azure 自动化活动
Microsoft.Automation/automationAccounts/nodeConfigurations/rawContent/action 读取 Azure Automation DSC 的节点配置内容
Microsoft.Automation/automationAccounts/nodeConfigurations/read 读取 Azure Automation DSC 的节点配置
Microsoft.Automation/automationAccounts/nodeConfigurations/write 写入 Azure Automation DSC 的节点配置
Microsoft.Automation/automationAccounts/nodeConfigurations/delete 删除 Azure Automation DSC 的节点配置
Microsoft.Automation/automationAccounts/nodecounts/read 读取指定类型的节点计数摘要
Microsoft.Automation/automationAccounts/nodes/read 读取 Azure Automation DSC 节点
Microsoft.Automation/automationAccounts/nodes/write 创建或更新 Azure Automation DSC 节点
Microsoft.Automation/automationAccounts/nodes/delete 删除 Azure Automation DSC 节点
Microsoft.Automation/automationAccounts/nodes/reports/read 读取 Azure Automation DSC 报表
Microsoft.Automation/automationAccounts/nodes/reports/content/read 读取 Azure Automation DSC 报表内容
Microsoft.Automation/automationAccounts/objectDataTypes/fields/read 获取 Azure 自动化 TypeField
Microsoft.Automation/automationAccounts/privateEndpointConnectionProxies/read 读取 Azure 自动化专用终结点连接代理
Microsoft.Automation/automationAccounts/privateEndpointConnectionProxies/write 创建 Azure 自动化专用终结点连接代理
Microsoft.Automation/automationAccounts/privateEndpointConnectionProxies/validate/action 验证专用终结点连接请求(groupId 验证)
Microsoft.Automation/automationAccounts/privateEndpointConnectionProxies/delete 删除 Azure 自动化专用终结点连接代理
Microsoft.Automation/automationAccounts/privateEndpointConnectionProxies/operationResults/read 获取 Azure 自动化专用终结点代理操作结果。
Microsoft.Automation/automationAccounts/privateEndpointConnections/read 获取 Azure 自动化专用终结点连接状态
Microsoft.Automation/automationAccounts/privateEndpointConnections/write 批准或拒绝 Azure 自动化专用终结点连接
Microsoft.Automation/automationAccounts/privateEndpointConnections/delete 删除 Azure 自动化专用终结点连接
Microsoft.Automation/automationAccounts/privateLinkResources/read 读取专用终结点的组信息
Microsoft.Automation/automationAccounts/providers/Microsoft.Insights/metricDefinitions/read 获取自动化指标定义
Microsoft.Automation/automationAccounts/python2Packages/read 获取 Azure 自动化 Python 2 包
Microsoft.Automation/automationAccounts/python2Packages/write 创建或更新 Azure 自动化 Python 2 包
Microsoft.Automation/automationAccounts/python2Packages/delete 删除 Azure 自动化 Python 2 包
Microsoft.Automation/automationAccounts/python3Packages/read 获取 Azure 自动化 Python 3 包
Microsoft.Automation/automationAccounts/python3Packages/write 创建或更新 Azure 自动化 Python 3 包
Microsoft.Automation/automationAccounts/python3Packages/delete 删除 Azure 自动化 Python 3 包
Microsoft.Automation/automationAccounts/runbooks/read 获取 Azure 自动化 Runbook
Microsoft.Automation/automationAccounts/runbooks/getCount/action 获取 Azure 自动化 Runbook 的计数
Microsoft.Automation/automationAccounts/runbooks/write 创建或更新 Azure 自动化 Runbook
Microsoft.Automation/automationAccounts/runbooks/delete 删除 Azure 自动化 Runbook
Microsoft.Automation/automationAccounts/runbooks/publish/action 发布 Azure 自动化 Runbook 草稿
Microsoft.Automation/automationAccounts/runbooks/content/read 获取 Azure 自动化 Runbook 的内容
Microsoft.Automation/automationAccounts/runbooks/draft/read 获取 Azure 自动化 Runbook 草稿
Microsoft.Automation/automationAccounts/runbooks/draft/undoEdit/action 撤消对 Azure 自动化 Runbook 草稿的编辑
Microsoft.Automation/automationAccounts/runbooks/draft/write 创建 Azure 自动化 runbook 草稿
Microsoft.Automation/automationAccounts/runbooks/draft/content/write 创建 Azure 自动化 Runbook 草稿的内容
Microsoft.Automation/automationAccounts/runbooks/draft/operationResults/read 获取 Azure 自动化 Runbook 草稿操作结果
Microsoft.Automation/automationAccounts/runbooks/draft/testJob/read 获取 Azure 自动化 Runbook 草稿测试作业
Microsoft.Automation/automationAccounts/runbooks/draft/testJob/write 创建 Azure 自动化 Runbook 草稿测试作业
Microsoft.Automation/automationAccounts/runbooks/draft/testJob/stop/action 停止 Azure 自动化 Runbook 草稿测试作业
Microsoft.Automation/automationAccounts/runbooks/draft/testJob/suspend/action 暂停 Azure 自动化 Runbook 草稿测试作业
Microsoft.Automation/automationAccounts/runbooks/draft/testJob/resume/action 恢复 Azure 自动化 Runbook 草稿测试作业
Microsoft.Automation/automationAccounts/runbooks/operationResults/read 获取 Azure 自动化 Runbook 操作结果
Microsoft.Automation/automationAccounts/schedules/read 获取 Azure 自动化计划资产
Microsoft.Automation/automationAccounts/schedules/getCount/action 获取 Azure 自动化计划的计数
Microsoft.Automation/automationAccounts/schedules/write 创建或更新 Azure 自动化计划资产
Microsoft.Automation/automationAccounts/schedules/delete 删除 Azure 自动化计划资产
Microsoft.Automation/automationAccounts/softwareUpdateConfigurationMachineRuns/read 获取 Azure 自动化软件更新配置计算机运行
Microsoft.Automation/automationAccounts/softwareUpdateConfigurationRuns/read 获取 Azure 自动化软件更新配置运行
Microsoft.Automation/automationAccounts/softwareUpdateConfigurations/write 创建或更新 Azure 自动化软件更新配置
Microsoft.Automation/automationAccounts/softwareUpdateConfigurations/read 获取 Azure 自动化软件更新配置
Microsoft.Automation/automationAccounts/softwareUpdateConfigurations/delete 删除 Azure 自动化软件更新配置
Microsoft.Automation/automationAccounts/statistics/read 获取 Azure 自动化统计信息
Microsoft.Automation/automationAccounts/updateDeploymentMachineRuns/read 获取 Azure 自动化更新部署计算机
Microsoft.Automation/automationAccounts/updateManagementPatchJob/read 获取 Azure 自动化更新管理修补程序作业
Microsoft.Automation/automationAccounts/usages/read 获取 Azure 自动化使用情况
Microsoft.Automation/automationAccounts/variables/read 读取 Azure 自动化变量资产
Microsoft.Automation/automationAccounts/variables/write 创建或更新 Azure 自动化变量资产
Microsoft.Automation/automationAccounts/variables/delete 删除 Azure 自动化变量资产
Microsoft.Automation/automationAccounts/watchers/write 创建 Azure 自动化观察程序作业
Microsoft.Automation/automationAccounts/watchers/read 获取 Azure 自动化观察程序作业
Microsoft.Automation/automationAccounts/watchers/delete 删除 Azure 自动化观察程序作业
Microsoft.Automation/automationAccounts/watchers/start/action 启动 Azure 自动化观察程序作业
Microsoft.Automation/automationAccounts/watchers/stop/action 停止 Azure 自动化观察程序作业
Microsoft.Automation/automationAccounts/watchers/streams/read 获取 Azure 自动化观察程序作业流
Microsoft.Automation/automationAccounts/watchers/watcherActions/write 创建 Azure 自动化观察程序作业操作
Microsoft.Automation/automationAccounts/watchers/watcherActions/read 获取 Azure 自动化观察程序作业操作
Microsoft.Automation/automationAccounts/watchers/watcherActions/delete 删除 Azure 自动化观察程序作业操作
Microsoft.Automation/automationAccounts/webhooks/read 读取 Azure 自动化 Webhook
Microsoft.Automation/automationAccounts/webhooks/write 创建或更新 Azure 自动化 Webhook
Microsoft.Automation/automationAccounts/webhooks/delete 删除 Azure 自动化 Webhook
Microsoft.Automation/deletedAutomationAccounts/read 获取 Azure 自动化删除的帐户
Microsoft.Automation/operations/read 获取可对 Azure 自动化资源使用的操作

Microsoft.Billing

管理你的订阅并查看使用情况和计费信息。

Azure 服务:成本管理 + 计费

操作 说明
Microsoft.Billing/validateAddress/action
Microsoft.Billing/register/action
Microsoft.Billing/billingAccounts/read 列出可访问的计费帐户。
Microsoft.Billing/billingAccounts/write 更新计费帐户的属性。
Microsoft.Billing/billingAccounts/listInvoiceSectionsWithCreateSubscriptionPermission/action
Microsoft.Billing/billingAccounts/confirmTransition/action
Microsoft.Billing/billingAccounts/billingProfiles/action
Microsoft.Billing/billingAccounts/addDailyInvoicingOverrideTerms/write
Microsoft.Billing/billingAccounts/addDepartment/write
Microsoft.Billing/billingAccounts/addEnrollmentAccount/write
Microsoft.Billing/billingAccounts/addPaymentTerms/write
Microsoft.Billing/billingAccounts/agreements/read
Microsoft.Billing/billingAccounts/alertPreferences/write 为指定的计费帐户创建或更新 AlertPreference。
Microsoft.Billing/billingAccounts/alertPreferences/read 获取具有给定 ID 的 AlertPreference。
Microsoft.Billing/billingAccounts/alerts/read 按 ID 获取警报定义。
Microsoft.Billing/billingAccounts/associatedTenants/read 列出可以就商务活动(例如查看和下载发票、管理付款、购买产品和管理许可证)与计费帐户进行协作的租户。
Microsoft.Billing/billingAccounts/associatedTenants/write 创建或更新计费帐户的关联租户。
Microsoft.Billing/billingAccounts/billingPermissions/read
Microsoft.Billing/billingAccounts/billingProfiles/read
Microsoft.Billing/billingAccounts/billingProfiles/write
Microsoft.Billing/billingAccounts/billingProfiles/purchaseProduct/action
Microsoft.Billing/billingAccounts/billingProfiles/priceProduct/action
Microsoft.Billing/billingAccounts/billingProfiles/invoiceSections/action
Microsoft.Billing/billingAccounts/billingProfiles/alerts/read 列出计费配置文件的警报。 协议类型为 Microsoft 客户协议和 Microsoft 合作伙伴协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/billingProfiles/billingPermissions/read
Microsoft.Billing/billingAccounts/billingProfiles/billingRoleDefinitions/read 获取计费配置文件中某个角色的定义。 协议类型为 Microsoft 合作伙伴协议或 Microsoft 客户协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/billingProfiles/billingSubscriptions/read 按计费配置文件 ID 和计费订阅 ID 获取计费订阅。 只有企业协议类型的计费帐户支持此操作。
Microsoft.Billing/billingAccounts/billingProfiles/checkAccess/write
Microsoft.Billing/billingAccounts/billingProfiles/customers/read
Microsoft.Billing/billingAccounts/billingProfiles/customers/billingPermissions/read
Microsoft.Billing/billingAccounts/billingProfiles/customers/billingRoleDefinitions/read 获取客户角色的定义。 只有协议类型为 Microsoft 合作伙伴协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/billingProfiles/customers/checkAccess/write
Microsoft.Billing/billingAccounts/billingProfiles/customers/resolveBillingRoleAssignments/write
Microsoft.Billing/billingAccounts/billingProfiles/departments/read 列出用户有权访问的部门。 只有协议类型为企业协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/billingProfiles/departments/billingPermissions/read
Microsoft.Billing/billingAccounts/billingProfiles/departments/billingRoleDefinitions/read 获取部门中某个角色的定义。 协议类型为企业协议的计费配置文件支持该操作。
Microsoft.Billing/billingAccounts/billingProfiles/departments/billingSubscriptions/read 按计费配置文件 ID 和部门名称列出计费订阅。 只有企业协议类型的计费帐户支持此操作。
Microsoft.Billing/billingAccounts/billingProfiles/departments/enrollmentAccounts/read 使用计费配置文件 ID 和部门 ID 获取注册帐户列表
Microsoft.Billing/billingAccounts/billingProfiles/enrollmentAccounts/read 列出特定计费帐户及其下级计费配置文件的注册帐户。
Microsoft.Billing/billingAccounts/billingProfiles/enrollmentAccounts/billingPermissions/read
Microsoft.Billing/billingAccounts/billingProfiles/enrollmentAccounts/billingSubscriptions/read 按计费配置文件 ID 和注册帐户名称列出计费订阅。 只有企业协议类型的计费帐户支持此操作。
Microsoft.Billing/billingAccounts/billingProfiles/invoices/download/action
Microsoft.Billing/billingAccounts/billingProfiles/invoices/pricesheet/download/action
Microsoft.Billing/billingAccounts/billingProfiles/invoices/validateRefundEligibility/write
Microsoft.Billing/billingAccounts/billingProfiles/invoiceSections/read 列出用户有权访问的发票科目。 只有协议类型为 Microsoft 客户协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/billingProfiles/invoiceSections/write 创建或更新发票科目。 只有协议类型为 Microsoft 客户协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/billingProfiles/invoiceSections/billingPermissions/read
Microsoft.Billing/billingAccounts/billingProfiles/invoiceSections/billingRoleDefinitions/read 获取发票科目中某个角色的定义。 只有协议类型为 Microsoft 客户协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/billingProfiles/invoiceSections/billingSubscriptions/transfer/action
Microsoft.Billing/billingAccounts/billingProfiles/invoiceSections/billingSubscriptions/move/action
Microsoft.Billing/billingAccounts/billingProfiles/invoiceSections/billingSubscriptions/validateMoveEligibility/action
Microsoft.Billing/billingAccounts/billingProfiles/invoiceSections/billingSubscriptions/write
Microsoft.Billing/billingAccounts/billingProfiles/invoiceSections/billingSubscriptions/read 列出在发票科目中计费的订阅。 只有协议类型为 Microsoft 客户协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/billingProfiles/invoiceSections/checkAccess/write
Microsoft.Billing/billingAccounts/billingProfiles/invoiceSections/products/transfer/action
Microsoft.Billing/billingAccounts/billingProfiles/invoiceSections/products/move/action
Microsoft.Billing/billingAccounts/billingProfiles/invoiceSections/products/validateMoveEligibility/action
Microsoft.Billing/billingAccounts/billingProfiles/invoiceSections/resolveBillingRoleAssignments/write
Microsoft.Billing/billingAccounts/billingProfiles/invoiceSections/validateDeleteEligibility/write 验证是否可以删除发票科目。 协议类型为 Microsoft 客户协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/billingProfiles/invoiceSections/validateDeleteInvoiceSectionEligibility/write
Microsoft.Billing/billingAccounts/billingProfiles/notificationContacts/read 列出给定计费配置文件的 NotificationContacts。 只有协议类型为企业协议的计费配置文件支持该操作。
Microsoft.Billing/billingAccounts/billingProfiles/policies/read 列出计费配置文件的策略。 只有协议类型为 Microsoft 客户协议的计费帐户支持此操作。
Microsoft.Billing/billingAccounts/billingProfiles/policies/write 更新计费配置文件的策略。 只有协议类型为 Microsoft 客户协议的计费帐户支持此操作。
Microsoft.Billing/billingAccounts/billingProfiles/pricesheet/download/action
Microsoft.Billing/billingAccounts/billingProfiles/products/read
Microsoft.Billing/billingAccounts/billingProfiles/resolveBillingRoleAssignments/write
Microsoft.Billing/billingAccounts/billingProfiles/validateDeleteBillingProfileEligibility/write
Microsoft.Billing/billingAccounts/billingProfiles/validateRefundEligibility/write 验证计费配置文件是否有任何符合加速退款条件的发票。 协议类型为 Microsoft 客户协议和帐户类型个人的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/billingProfilesSummaries/read 获取计费帐户下的计费配置文件摘要。 协议类型为企业协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/billingRoleAssignments/write
Microsoft.Billing/billingAccounts/billingRoleDefinitions/read 获取计费帐户中某个角色的定义。 协议类型为 Microsoft 合作伙伴协议、Microsoft 客户协议或企业协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/billingSubscriptionAliases/read
Microsoft.Billing/billingAccounts/billingSubscriptionAliases/write
Microsoft.Billing/billingAccounts/billingSubscriptions/read 列出计费帐户的订阅。 协议类型为 Microsoft 客户协议、Microsoft 合作伙伴协议或企业协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/billingSubscriptions/downloadDocuments/action 使用列表中的下载链接下载发票
Microsoft.Billing/billingAccounts/billingSubscriptions/move/action
Microsoft.Billing/billingAccounts/billingSubscriptions/validateMoveEligibility/action
Microsoft.Billing/billingAccounts/billingSubscriptions/write 更新计费订阅的属性。 只能更新协议类型为 Microsoft 客户协议的计费帐户的成本中心。
Microsoft.Billing/billingAccounts/billingSubscriptions/cancel/write 取消 Azure 计费订阅。
Microsoft.Billing/billingAccounts/billingSubscriptions/enable/write 启用 Azure 计费订阅。
Microsoft.Billing/billingAccounts/billingSubscriptions/merge/write
Microsoft.Billing/billingAccounts/billingSubscriptions/move/write 将订阅的费用移动到新的发票科目。 新发票科目必须与现有发票科目属于同一计费配置文件。 协议类型为 Microsoft 客户协议的计费帐户支持此操作。
Microsoft.Billing/billingAccounts/billingSubscriptions/split/write
Microsoft.Billing/billingAccounts/billingSubscriptions/validateMoveEligibility/write 验证是否可以将订阅的费用移动到新的发票科目。 协议类型为 Microsoft 客户协议的计费帐户支持此操作。
Microsoft.Billing/billingAccounts/cancelDailyInvoicingOverrideTerms/write
Microsoft.Billing/billingAccounts/cancelPaymentTerms/write
Microsoft.Billing/billingAccounts/checkAccess/write
Microsoft.Billing/billingAccounts/customers/read
Microsoft.Billing/billingAccounts/customers/initiateTransfer/action
Microsoft.Billing/billingAccounts/customers/billingPermissions/read
Microsoft.Billing/billingAccounts/customers/billingSubscriptions/read 列出客户的订阅。 只有协议类型为 Microsoft 合作伙伴协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/customers/checkAccess/write
Microsoft.Billing/billingAccounts/customers/policies/read 列出客户的策略。 只有协议类型为 Microsoft 合作伙伴协议的计费帐户支持此操作。
Microsoft.Billing/billingAccounts/customers/policies/write 更新客户的策略。 只有协议类型为 Microsoft 合作伙伴协议的计费帐户支持此操作。
Microsoft.Billing/billingAccounts/customers/resolveBillingRoleAssignments/write
Microsoft.Billing/billingAccounts/customers/transfers/write
Microsoft.Billing/billingAccounts/customers/transfers/read
Microsoft.Billing/billingAccounts/departments/read 列出用户有权访问的部门。 只有协议类型为企业协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/departments/write
Microsoft.Billing/billingAccounts/departments/addEnrollmentAccount/write
Microsoft.Billing/billingAccounts/departments/billingPermissions/read
Microsoft.Billing/billingAccounts/departments/billingRoleAssignments/write
Microsoft.Billing/billingAccounts/departments/billingRoleDefinitions/read 获取部门中某个角色的定义。 协议类型为企业协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/departments/billingSubscriptions/read 列出部门的订阅。 协议类型为企业协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/departments/checkAccess/write
Microsoft.Billing/billingAccounts/departments/enrollmentAccounts/read 列出部门的注册帐户。 只有协议类型为企业协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/departments/enrollmentAccounts/write
Microsoft.Billing/billingAccounts/departments/enrollmentAccounts/remove/write
Microsoft.Billing/billingAccounts/enrollmentAccounts/read 列出计费帐户的注册帐户。 只有协议类型为企业协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/enrollmentAccounts/write
Microsoft.Billing/billingAccounts/enrollmentAccounts/activate/write
Microsoft.Billing/billingAccounts/enrollmentAccounts/activationStatus/read
Microsoft.Billing/billingAccounts/enrollmentAccounts/billingPermissions/read
Microsoft.Billing/billingAccounts/enrollmentAccounts/billingRoleAssignments/write
Microsoft.Billing/billingAccounts/enrollmentAccounts/billingRoleDefinitions/read 获取注册帐户中某个角色的定义。 协议类型为企业协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/enrollmentAccounts/billingSubscriptions/write
Microsoft.Billing/billingAccounts/enrollmentAccounts/billingSubscriptions/read 列出注册帐户的订阅。 协议类型为企业协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/enrollmentAccounts/checkAccess/write
Microsoft.Billing/billingAccounts/enrollmentAccounts/transferBillingSubscriptions/write
Microsoft.Billing/billingAccounts/invoices/download/action
Microsoft.Billing/billingAccounts/invoices/pricesheet/download/action
Microsoft.Billing/billingAccounts/invoiceSections/write
Microsoft.Billing/billingAccounts/invoiceSections/elevate/action
Microsoft.Billing/billingAccounts/invoiceSections/read
Microsoft.Billing/billingAccounts/listBillingProfilesWithViewPricesheetPermissions/read
Microsoft.Billing/billingAccounts/listProductRecommendations/write 列出建议在帐户上购买的 ProductId 或 offerId。 请将“x-ms-recommendations-cohort-type”标头中计费帐户的队列类型指定为所需的字符串参数。
Microsoft.Billing/billingAccounts/notificationContacts/read 列出给定计费帐户的 NotificationContacts。 只有协议类型为企业协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/notificationContacts/write 按 ID 更新通知联系人。 只有协议类型为企业协议的计费帐户支持该操作。
Microsoft.Billing/billingAccounts/operationResults/read
Microsoft.Billing/billingAccounts/policies/read 获取企业协议类型的计费帐户的策略。
Microsoft.Billing/billingAccounts/policies/write 更新企业协议类型的计费帐户的策略。
Microsoft.Billing/billingAccounts/products/read
Microsoft.Billing/billingAccounts/products/move/action
Microsoft.Billing/billingAccounts/products/validateMoveEligibility/action
Microsoft.Billing/billingAccounts/purchaseProduct/write
Microsoft.Billing/billingAccounts/resolveBillingRoleAssignments/write
Microsoft.Billing/billingAccounts/validateDailyInvoicingOverrideTerms/write
Microsoft.Billing/billingAccounts/validatePaymentTerms/write
Microsoft.Billing/billingPeriods/read
Microsoft.Billing/billingProperty/read
Microsoft.Billing/billingProperty/write
Microsoft.Billing/departments/read
Microsoft.Billing/enrollmentAccounts/read
Microsoft.Billing/invoices/read
Microsoft.Billing/invoices/download/action 使用列表中的下载链接下载发票
Microsoft.Billing/operations/read 提供程序支持的操作列表。
Microsoft.Billing/policies/read
Microsoft.Billing/promotions/read 列出或获取促销
Microsoft.Billing/validateAddress/write

Microsoft.Blueprint

实现受治理环境的快速可重复创建。

Azure 服务:Azure 蓝图

操作 说明
Microsoft.Blueprint/register/action 注册 Azure 蓝图资源提供程序
Microsoft.Blueprint/blueprintAssignments/read 读取任何蓝图项目
Microsoft.Blueprint/blueprintAssignments/write 创建或更新任何蓝图项目
Microsoft.Blueprint/blueprintAssignments/delete 删除任何蓝图项目
Microsoft.Blueprint/blueprintAssignments/whoisblueprint/action 获取 Azure 蓝图服务主体对象 ID。
Microsoft.Blueprint/blueprintAssignments/assignmentOperations/read 读取任何蓝图项目
Microsoft.Blueprint/blueprints/read 读取任何蓝图
Microsoft.Blueprint/blueprints/write 创建或更新任何蓝图
Microsoft.Blueprint/blueprints/delete 删除任何蓝图
Microsoft.Blueprint/blueprints/artifacts/read 读取任何蓝图项目
Microsoft.Blueprint/blueprints/artifacts/write 创建或更新任何蓝图项目
Microsoft.Blueprint/blueprints/artifacts/delete 删除任何蓝图项目
Microsoft.Blueprint/blueprints/versions/read 读取任何蓝图
Microsoft.Blueprint/blueprints/versions/write 创建或更新任何蓝图
Microsoft.Blueprint/blueprints/versions/delete 删除任何蓝图
Microsoft.Blueprint/blueprints/versions/artifacts/read 读取任何蓝图项目

Microsoft.Consumption

对 Azure 资源的成本和使用情况数据进行编程访问。

Azure 服务:成本管理

操作 说明
Microsoft.Consumption/register/action 注册到消耗 RP
Microsoft.Consumption/aggregatedcost/read 列出管理组的 AggregatedCost。
Microsoft.Consumption/balances/read 列出管理组的计费周期的使用情况摘要。
Microsoft.Consumption/budgets/read 按订阅或管理组列出预算。
Microsoft.Consumption/budgets/write 按订阅或管理组创建和更新预算。
Microsoft.Consumption/budgets/delete 按订阅或管理组删除预算。
Microsoft.Consumption/charges/read 列出费用
Microsoft.Consumption/credits/read 列出信用额度
Microsoft.Consumption/events/read 列出事件
Microsoft.Consumption/externalBillingAccounts/tags/read 列出 EA 和订阅的标记。
Microsoft.Consumption/externalSubscriptions/tags/read 列出 EA 和订阅的标记。
Microsoft.Consumption/forecasts/read 列出预测
Microsoft.Consumption/lots/read 列出批次
Microsoft.Consumption/marketplaces/read 列出 EA 和 WebDirect 订阅的市场资源使用情况。
Microsoft.Consumption/operationresults/read 列出 operationresults
Microsoft.Consumption/operations/read 列出 Microsoft.Consumption 资源提供程序支持的所有操作。
Microsoft.Consumption/operationstatus/read 列出 operationstatus
Microsoft.Consumption/pricesheets/read 列出订阅或管理组的 Pricesheets 数据。
Microsoft.Consumption/reservationDetails/read 按预订订单或管理组列出保留实例的使用情况详细信息。 详细信息数据为每天每个实例级别。
Microsoft.Consumption/reservationRecommendationDetails/read 列出预留建议详细信息
Microsoft.Consumption/reservationRecommendations/read 列出某个订阅的预留实例的单个或共享建议。
Microsoft.Consumption/reservationSummaries/read 按预订订单或管理组列出保留实例的使用情况详细信息。 摘要数据为每月或每天级别。
Microsoft.Consumption/reservationTransactions/read 按管理组列出预留实例的事务历史记录。
Microsoft.Consumption/tags/read 列出 EA 和订阅的标记。
Microsoft.Consumption/tenants/register/action 按租户注册 Microsoft.Consumption 的作用域的操作。
Microsoft.Consumption/tenants/read 列出租户
Microsoft.Consumption/terms/read 列出订阅或管理组的条款。
Microsoft.Consumption/usageDetails/read 列出 EA 和 WebDirect 订阅的范围的使用情况详细信息。

Microsoft.Features

Azure 服务:Azure Resource Manager

操作 说明
Microsoft.Features/register/action 注册某个订阅的功能。
Microsoft.Features/featureProviders/subscriptionFeatureRegistrations/read 获取给定资源提供程序中某个订阅的功能注册。
Microsoft.Features/featureProviders/subscriptionFeatureRegistrations/write 添加给定资源提供程序中某个订阅的功能注册。
Microsoft.Features/featureProviders/subscriptionFeatureRegistrations/delete 删除给定资源提供程序中某个订阅的功能注册。
Microsoft.Features/features/read 获取订阅的功能。
Microsoft.Features/operations/read 获取操作列表。
Microsoft.Features/providers/features/read 获取给定资源提供程序中某个订阅的功能。
Microsoft.Features/providers/features/register/action 在给定的资源提供程序中注册某个订阅的功能。
Microsoft.Features/providers/features/unregister/action 取消注册给定资源提供程序中的订阅的功能。
Microsoft.Features/subscriptionFeatureRegistrations/read 获取某个订阅的功能注册。

Microsoft.GuestConfiguration

使用 Azure Policy 审核计算机内部设置。

Azure 服务:Azure Policy

操作 说明
Microsoft.GuestConfiguration/register/action 注册 Microsoft.GuestConfiguration 资源提供程序的订阅。
Microsoft.GuestConfiguration/guestConfigurationAssignments/write 创建新的来宾配置分配。
Microsoft.GuestConfiguration/guestConfigurationAssignments/read 获取来宾配置分配。
Microsoft.GuestConfiguration/guestConfigurationAssignments/delete 删除来宾配置分配。
Microsoft.GuestConfiguration/guestConfigurationAssignments/healthcheck/action 获取来宾配置分配。
Microsoft.GuestConfiguration/guestConfigurationAssignments/reports/read 获取来宾配置分配报告。
Microsoft.GuestConfiguration/operations/read 获取 Microsoft.GuestConfiguration 资源提供程序的操作

Microsoft.Intune

使员工能够在其所有设备上保持高效率,同时保护组织信息的安全。

Azure 服务:Microsoft Monitoring Insights

操作 说明
Microsoft.Intune/diagnosticsettings/write 写入诊断设置
Microsoft.Intune/diagnosticsettings/read 读取诊断设置
Microsoft.Intune/diagnosticsettings/delete 删除诊断设置
Microsoft.Intune/diagnosticsettingscategories/read 读取诊断设置类别

Microsoft.ManagedServices

Azure 服务:Azure Lighthouse

操作 说明
Microsoft.ManagedServices/register/action 注册到托管服务。
Microsoft.ManagedServices/unregister/action 从托管服务取消注册。
Microsoft.ManagedServices/marketplaceRegistrationDefinitions/read 检索托管服务注册定义的列表。
Microsoft.ManagedServices/operations/read 检索托管服务操作的列表。
Microsoft.ManagedServices/operationStatuses/read 读取资源的操作状态。
Microsoft.ManagedServices/registrationAssignments/read 检索托管服务注册分配的列表。
Microsoft.ManagedServices/registrationAssignments/write 添加或修改托管服务注册分配。
Microsoft.ManagedServices/registrationAssignments/delete 删除托管服务注册分配。
Microsoft.ManagedServices/registrationDefinitions/read 检索托管服务注册定义的列表。
Microsoft.ManagedServices/registrationDefinitions/write 添加或修改托管服务注册定义。
Microsoft.ManagedServices/registrationDefinitions/delete 删除托管服务注册定义。

Microsoft.Management

使用管理组有效地应用治理控制和管理 Azure 订阅组。

Azure 服务:管理组

操作 说明
Microsoft.Management/checkNameAvailability/action 检查指定的管理组名称是否有效且唯一。
Microsoft.Management/getEntities/action 列出已通过身份验证的用户的所有实体(管理组、订阅等)。
Microsoft.Management/register/action 向 Microsoft.Management 注册指定的订阅
Microsoft.Management/managementGroups/read 列出已通过身份验证的用户的管理组。
Microsoft.Management/managementGroups/write 创建或更新管理组。
Microsoft.Management/managementGroups/delete 删除管理组。
Microsoft.Management/managementGroups/descendants/read 获取管理组的所有后代(管理组、订阅)。
Microsoft.Management/managementGroups/settings/read 列出现有的管理组层次结构设置。
Microsoft.Management/managementGroups/settings/write 创建或更新管理组层次结构设置。
Microsoft.Management/managementGroups/settings/delete 删除管理组层次结构设置。
Microsoft.Management/managementGroups/subscriptions/read 列出给定管理组下的订阅。
Microsoft.Management/managementGroups/subscriptions/write 将现有订阅与管理组关联。
Microsoft.Management/managementGroups/subscriptions/delete 从管理组取消关联订阅。

Microsoft.PolicyInsights

汇总订阅级别策略定义的策略状态。

Azure 服务:Azure Policy

操作 说明
Microsoft.PolicyInsights/register/action 注册 Microsoft 策略见解资源提供程序,并启用对其执行的操作。
Microsoft.PolicyInsights/unregister/action 注销 Microsoft 策略见解资源提供程序。
Microsoft.PolicyInsights/asyncOperationResults/read 获取异步操作结果。
Microsoft.PolicyInsights/attestations/read 获取符合性状态证明。
Microsoft.PolicyInsights/attestations/write 创建或更新符合性状态证明。
Microsoft.PolicyInsights/attestations/delete 删除符合性状态证明。
Microsoft.PolicyInsights/checkPolicyRestrictions/read 详细了解策略将对资源强制实施的限制。
Microsoft.PolicyInsights/componentPolicyStates/queryResults/read 查询有关组件策略状态的信息。
Microsoft.PolicyInsights/eventGridFilters/read 获取用于跟踪要为哪些范围发布状态更改通知的事件网格筛选器。
Microsoft.PolicyInsights/eventGridFilters/write 创建或更新事件网格筛选器。
Microsoft.PolicyInsights/eventGridFilters/delete 删除事件网格筛选器。
Microsoft.PolicyInsights/operations/read 获取 Microsoft.PolicyInsights 命名空间支持的操作
Microsoft.PolicyInsights/policyEvents/queryResults/action 查询有关策略事件的信息。
Microsoft.PolicyInsights/policyEvents/queryResults/read 查询有关策略事件的信息。
Microsoft.PolicyInsights/policyMetadata/read 获取策略元数据资源。
Microsoft.PolicyInsights/policyStates/queryResults/action 查询有关策略状态的信息。
Microsoft.PolicyInsights/policyStates/summarize/action 查询有关策略最新状态的摘要信息。
Microsoft.PolicyInsights/policyStates/triggerEvaluation/action 为所选范围触发新的符合性评估。
Microsoft.PolicyInsights/policyStates/queryResults/read 查询有关策略状态的信息。
Microsoft.PolicyInsights/policyStates/summarize/read 查询有关策略最新状态的摘要信息。
Microsoft.PolicyInsights/policyTrackedResources/queryResults/read 查询有关 DeployIfNotExists 策略所需的资源的信息。
Microsoft.PolicyInsights/remediations/read 获取策略修正。
Microsoft.PolicyInsights/remediations/write 创建或更新 Microsoft 策略修正。
Microsoft.PolicyInsights/remediations/delete 删除策略修正。
Microsoft.PolicyInsights/remediations/cancel/action 取消正在进行的 Microsoft 策略修正。
Microsoft.PolicyInsights/remediations/listDeployments/read 列出策略修正所需的部署。
DataAction 说明
Microsoft.PolicyInsights/checkDataPolicyCompliance/action 参照数据策略检查给定组件的合规性状态。
Microsoft.PolicyInsights/policyEvents/logDataEvents/action 记录资源组件策略事件。

Microsoft.Portal

在单个统一的控制台中生成、管理和监视所有 Azure 产品。

Azure 服务:Azure 门户

操作 说明
Microsoft.Portal/register/action 注册到门户
Microsoft.Portal/dashboards/read 读取订阅的仪表板。
Microsoft.Portal/dashboards/write 向订阅添加仪表板或修改仪表板。
Microsoft.Portal/dashboards/delete 从订阅删除仪表板。
Microsoft.Portal/tenantConfigurations/read 读取租户配置
Microsoft.Portal/tenantConfigurations/write 添加或更新租户配置。 用户必须是租户管理员,才能执行此操作。
Microsoft.Portal/tenantConfigurations/delete 删除租户配置。 用户必须是租户管理员,才能执行此操作。

Microsoft.RecoveryServices

保留并组织如 IaaS VM (Linux 或 Windows)等各种 Azure 服务以及 Azure SQL 数据库的备份数据。

Azure 服务:站点恢复

操作 说明
Microsoft.RecoveryServices/register/action 注册给定资源提供程序的订阅
Microsoft.RecoveryServices/unregister/action 注销给定资源提供程序的订阅
Microsoft.RecoveryServices/Locations/backupCrossRegionRestore/action 触发跨区域还原。
Microsoft.RecoveryServices/Locations/backupCrrJob/action 获取恢复服务保管库的次要区域中的跨区域还原作业详细信息。
Microsoft.RecoveryServices/Locations/backupCrrJobs/action 列出恢复服务保管库的次要区域中的跨区域还原作业。
Microsoft.RecoveryServices/Locations/backupPreValidateProtection/action
Microsoft.RecoveryServices/Locations/backupStatus/action 检查恢复服务保管库的备份状态
Microsoft.RecoveryServices/Locations/backupValidateFeatures/action 验证功能
Microsoft.RecoveryServices/locations/allocateStamp/action AllocateStamp 是服务使用的内部操作
Microsoft.RecoveryServices/locations/checkNameAvailability/action “检查资源名称性”是一个 API,用于检查资源名称是否可用
Microsoft.RecoveryServices/locations/allocatedStamp/read GetAllocatedStamp 是服务使用的内部操作
Microsoft.RecoveryServices/Locations/backupAadProperties/read 获取用于在第三区域进行身份验证的 AAD 属性,以便进行跨区域还原。
Microsoft.RecoveryServices/Locations/backupCrrOperationResults/read 返回恢复服务保管库的 CRR 操作结果。
Microsoft.RecoveryServices/Locations/backupCrrOperationsStatus/read 返回恢复服务保管库的 CRR 操作状态。
Microsoft.RecoveryServices/Locations/backupProtectedItem/write 创建备份受保护项
Microsoft.RecoveryServices/Locations/backupProtectedItems/read 返回所有受保护项的列表。
Microsoft.RecoveryServices/locations/operationStatus/read 获取给定操作的操作状态
Microsoft.RecoveryServices/operations/read 操作返回资源提供程序的操作列表
Microsoft.RecoveryServices/Vaults/backupJobsExport/action 导出作业
Microsoft.RecoveryServices/Vaults/backupSecurityPIN/action 返回恢复服务保管库的安全 PIN 信息。
Microsoft.RecoveryServices/Vaults/backupTriggerValidateOperation/action 验证对受保护项的操作
Microsoft.RecoveryServices/Vaults/backupValidateOperation/action 验证对受保护项的操作
Microsoft.RecoveryServices/Vaults/write “创建保管库”操作创建“vault”类型的 Azure 资源
Microsoft.RecoveryServices/Vaults/read “获取保管库”操作获取表示“vault”类型的 Azure 资源的对象
Microsoft.RecoveryServices/Vaults/delete “删除保管库”操作删除“vault”类型的指定 Azure 资源
Microsoft.RecoveryServices/Vaults/backupconfig/read 返回恢复服务保管库的配置。
Microsoft.RecoveryServices/Vaults/backupconfig/write 更新恢复服务保管库的配置。
Microsoft.RecoveryServices/Vaults/backupDeletedProtectionContainers/read 返回属于订阅的所有容器
Microsoft.RecoveryServices/Vaults/backupEncryptionConfigs/read 获取备份资源加密配置。
Microsoft.RecoveryServices/Vaults/backupEncryptionConfigs/write 更新备份资源加密配置
Microsoft.RecoveryServices/Vaults/backupEngines/read 返回使用保管库注册的所有备份管理服务器。
Microsoft.RecoveryServices/Vaults/backupFabrics/refreshContainers/action 刷新容器列表
Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/delete 删除备份保护意向
Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/read 获取备份保护意向
Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/write 创建备份保护意向
Microsoft.RecoveryServices/Vaults/backupFabrics/operationResults/read 返回操作状态
Microsoft.RecoveryServices/Vaults/backupFabrics/operationsStatus/read 返回操作状态
Microsoft.RecoveryServices/Vaults/backupFabrics/protectableContainers/read 获取所有可保护的容器
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/delete 删除已注册的容器
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/inquire/action 在容器内进行工作负载的查询
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/read 返回所有已注册的容器
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/write 创建已注册的容器
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/items/read 获取容器中的所有项
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/operationResults/read 获取对保护容器执行的操作的结果。
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/operationsStatus/read 获取对保护容器执行的操作的状态。
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/backup/action 对受保护的项执行备份。
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/delete 删除受保护的项
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/read 返回受保护项的对象详细信息
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPointsRecommendedForMove/action 获取建议移动到其他层级的恢复点
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/write 创建备份受保护项
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/operationResults/read 获取对受保护项执行的操作的结果。
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/operationsStatus/read 返回对受保护项执行的操作的状态。
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/accessToken/action 获取跨区域还原所需的 AccessToken。
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/move/action 将恢复点移动到其他层级
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/provisionInstantItemRecovery/action 预配受保护项的即时项恢复
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/read 获取受保护项的恢复点。
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/restore/action 还原受保护项的恢复点。
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/revokeInstantItemRecovery/action 吊销受保护项的即时项恢复
Microsoft.RecoveryServices/Vaults/backupJobs/cancel/action 取消作业
Microsoft.RecoveryServices/Vaults/backupJobs/read 返回所有作业对象
Microsoft.RecoveryServices/Vaults/backupJobs/retry/action 取消作业
Microsoft.RecoveryServices/Vaults/backupJobs/backupChildJobs/read 返回所有作业对象
Microsoft.RecoveryServices/Vaults/backupJobs/operationResults/read 返回作业操作的结果。
Microsoft.RecoveryServices/Vaults/backupJobs/operationsStatus/read 返回作业操作的状态。
Microsoft.RecoveryServices/Vaults/backupOperationResults/read 返回恢复服务保管库的备份操作结果。
Microsoft.RecoveryServices/Vaults/backupOperations/read 返回恢复服务保管库的备份操作状态。
Microsoft.RecoveryServices/Vaults/backupPolicies/delete 删除保护策略
Microsoft.RecoveryServices/Vaults/backupPolicies/read 返回所有保护策略
Microsoft.RecoveryServices/Vaults/backupPolicies/write 创建保护策略
Microsoft.RecoveryServices/Vaults/backupPolicies/operationResults/read 获取策略操作的结果。
Microsoft.RecoveryServices/Vaults/backupPolicies/operations/read 获取策略操作的状态。
Microsoft.RecoveryServices/Vaults/backupProtectableItems/read 返回所有可保护项的列表。
Microsoft.RecoveryServices/Vaults/backupProtectedItems/read 返回所有受保护项的列表。
Microsoft.RecoveryServices/Vaults/backupProtectionContainers/read 返回属于订阅的所有容器
Microsoft.RecoveryServices/Vaults/backupProtectionIntents/read 列出所有备份保护意向
Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/delete “删除 ResourceGuard 代理”操作删除类型为“ResourceGuard 代理”的指定 Azure 资源
Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/read 获取资源的 ResourceGuard 代理列表
Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/read “获取 ResourceGuard 代理”操作获取表示类型为“ResourceGuard 代理”的 Azure 资源的对象
Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/unlockDelete/action “解锁删除 ResourceGuard 代理”操作解锁下一删除关键操作
Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/write “创建 ResourceGuard 代理”操作创建类型为“ResourceGuard 代理”的 Azure 资源
Microsoft.RecoveryServices/Vaults/backupstorageconfig/read 返回恢复服务保管库的存储配置。
Microsoft.RecoveryServices/Vaults/backupstorageconfig/write 更新恢复服务保管库的存储配置。
Microsoft.RecoveryServices/Vaults/backupTieringCost/fetchTieringCost/action 返回分层相关的成本信息。
Microsoft.RecoveryServices/Vaults/backupTieringCost/operationResults/read 返回为分层成本执行的操作的结果
Microsoft.RecoveryServices/Vaults/backupTieringCost/operationsStatus/read 返回为分层成本执行的操作的状态
Microsoft.RecoveryServices/Vaults/backupUsageSummaries/read 返回恢复服务的受保护项和受保护服务器的摘要。
Microsoft.RecoveryServices/Vaults/backupValidateOperationResults/read 验证对受保护项的操作
Microsoft.RecoveryServices/Vaults/backupValidateOperationsStatuses/read 验证对受保护项的操作
Microsoft.RecoveryServices/Vaults/certificates/write “更新资源证书”操作更新资源/保管库凭据证书。
Microsoft.RecoveryServices/Vaults/extendedInformation/read “获取扩展信息”操作获取表示“vault”类型的 Azure 资源的对象扩展信息
Microsoft.RecoveryServices/Vaults/extendedInformation/write “获取扩展信息”操作获取表示“vault”类型的 Azure 资源的对象扩展信息
Microsoft.RecoveryServices/Vaults/extendedInformation/delete “获取扩展信息”操作获取表示“vault”类型的 Azure 资源的对象扩展信息
Microsoft.RecoveryServices/Vaults/locations/capabilities/action 列出给定位置的功能。
Microsoft.RecoveryServices/Vaults/monitoringAlerts/read 获取恢复服务保管库的警报。
Microsoft.RecoveryServices/Vaults/monitoringAlerts/write 解决警报。
Microsoft.RecoveryServices/Vaults/monitoringConfigurations/read 获取恢复服务保管库通知配置。
Microsoft.RecoveryServices/Vaults/monitoringConfigurations/write 配置到恢复服务保管库的电子邮件通知。
Microsoft.RecoveryServices/Vaults/operationResults/read “获取操作结果”操作可用于获取异步提交的操作的操作状态和结果
Microsoft.RecoveryServices/Vaults/operationStatus/read 获取给定操作的操作状态
Microsoft.RecoveryServices/Vaults/privateEndpointConnectionProxies/delete 等候几分钟时间,并重试操作。 如果该问题仍然存在,请联系 Microsoft 支持部门。
Microsoft.RecoveryServices/Vaults/privateEndpointConnectionProxies/read 获取所有可保护的容器
Microsoft.RecoveryServices/Vaults/privateEndpointConnectionProxies/validate/action 获取所有可保护的容器
Microsoft.RecoveryServices/Vaults/privateEndpointConnectionProxies/write 获取所有可保护的容器
Microsoft.RecoveryServices/Vaults/privateEndpointConnectionProxies/operationsStatus/read 获取所有可保护的容器
Microsoft.RecoveryServices/Vaults/privateEndpointConnections/delete 删除专用终结点请求。 此调用由备份管理员执行。
Microsoft.RecoveryServices/Vaults/privateEndpointConnections/write 批准或拒绝专用终结点请求。 此调用由备份管理员执行。
Microsoft.RecoveryServices/Vaults/privateEndpointConnections/read 返回所有专用终结点连接。
Microsoft.RecoveryServices/Vaults/privateEndpointConnections/operationsStatus/read 返回专用终结点连接的操作状态。
Microsoft.RecoveryServices/Vaults/privateLinkResources/read 返回所有专用链接资源。
Microsoft.RecoveryServices/Vaults/providers/Microsoft.Insights/diagnosticSettings/read Azure 备份诊断
Microsoft.RecoveryServices/Vaults/providers/Microsoft.Insights/diagnosticSettings/write Azure 备份诊断
Microsoft.RecoveryServices/Vaults/providers/Microsoft.Insights/logDefinitions/read Azure 备份日志
Microsoft.RecoveryServices/Vaults/providers/Microsoft.Insights/metricDefinitions/read Azure 备份指标
Microsoft.RecoveryServices/Vaults/registeredIdentities/write “注册服务容器”操作可用于向恢复服务注册容器。
Microsoft.RecoveryServices/Vaults/registeredIdentities/read “获取容器”操作可用于获取针对资源注册的容器。
Microsoft.RecoveryServices/Vaults/registeredIdentities/delete “取消注册容器”操作可用于取消注册容器。
Microsoft.RecoveryServices/Vaults/registeredIdentities/operationResults/read “获取操作结果”操作可用于获取异步提交的操作的操作状态和结果
Microsoft.RecoveryServices/vaults/replicationAlertSettings/read 读取任何警报设置
Microsoft.RecoveryServices/vaults/replicationAlertSettings/write 创建或更新任何警报设置
Microsoft.RecoveryServices/vaults/replicationEvents/read 读取任何事件
Microsoft.RecoveryServices/vaults/replicationFabrics/read 读取任何结构
Microsoft.RecoveryServices/vaults/replicationFabrics/write 创建或更新任何结构
Microsoft.RecoveryServices/vaults/replicationFabrics/remove/action 删除结构
Microsoft.RecoveryServices/vaults/replicationFabrics/checkConsistency/action 检查结构的一致性
Microsoft.RecoveryServices/vaults/replicationFabrics/delete 删除任何结构
Microsoft.RecoveryServices/vaults/replicationFabrics/renewcertificate/action 续订 Fabric 的证书
Microsoft.RecoveryServices/vaults/replicationFabrics/deployProcessServerImage/action 部署进程服务器映像
Microsoft.RecoveryServices/vaults/replicationFabrics/reassociateGateway/action 重新关联网关
Microsoft.RecoveryServices/vaults/replicationFabrics/migratetoaad/action 将结构迁移到 AAD
Microsoft.RecoveryServices/vaults/replicationFabrics/moveWebApp/action 移动 WebApp
Microsoft.RecoveryServices/vaults/replicationFabrics/removeInfra/action
Microsoft.RecoveryServices/vaults/replicationFabrics/operationresults/read 跟踪对资源“结构”执行的异步操作的结果
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationLogicalNetworks/read 读取任何逻辑网络
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/read 读取任何网络
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/replicationNetworkMappings/read 读取任何网络映射
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/replicationNetworkMappings/write 创建或更新任何网络映射
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/replicationNetworkMappings/delete 删除任何网络映射
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/read 读取任何保护容器
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/discoverProtectableItem/action 发现可保护项
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/write 创建或更新任何保护容器
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/remove/action 删除保护容器
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/switchprotection/action 交换保护容器
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/operationresults/read 跟踪对资源“保护容器”执行的异步操作的结果
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/read 读取任何迁移项
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/write 创建或更新任何迁移项
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/delete 删除任何迁移项
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/resync/action 重新同步
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/migrate/action 迁移项
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/testMigrate/action 测试迁移
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/testMigrateCleanup/action 测试迁移清理
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/pauseReplication/action
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/resumeReplication/action
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/migrationRecoveryPoints/read 读取任何迁移恢复点
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/operationresults/read 跟踪对资源“迁移项”执行的异步操作的结果
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectableItems/read 读取任何可保护项
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/read 读取任何受保护项
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/write 创建或更新任何受保护的项
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/delete 删除任何受保护的项
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/remove/action 删除受保护的项
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/plannedFailover/action 计划内故障转移
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/unplannedFailover/action 故障转移
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/testFailover/action 测试故障转移
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/testFailoverCleanup/action 测试故障转移清理
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/failoverCommit/action 故障转移提交
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/reProtect/action 重新保护受保护的项
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/updateMobilityService/action 更新移动服务
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/repairReplication/action 修复复制
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/applyRecoveryPoint/action 应用还原点
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/submitFeedback/action 提交反馈
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/addDisks/action 添加磁盘
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/removeDisks/action 删除磁盘
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/ResolveHealthErrors/action
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/failoverCancel/action 故障转移取消
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/updateAppliance/action
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/operationresults/read 跟踪对资源“受保护的项”执行的异步操作的结果
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/recoveryPoints/read 读取任何复制恢复点
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/targetComputeSizes/read 读取任何目标计算大小
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionContainerMappings/read 读取任何保护容器映射
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionContainerMappings/write 创建或更新任何保护容器映射
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionContainerMappings/remove/action 删除保护容器映射
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionContainerMappings/delete 删除任何保护容器映射
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionContainerMappings/operationresults/read 跟踪对资源“保护容器映射”执行的异步操作的结果
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/read 读取任何恢复服务提供程序
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/write 创建或更新任何恢复服务提供程序
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/remove/action 删除恢复服务提供程序
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/delete 删除任何恢复服务提供程序
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/refreshProvider/action 刷新提供程序
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/operationresults/read 跟踪对资源“恢复服务提供程序”执行的异步操作的结果
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/read 读取任何存储分类
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/replicationStorageClassificationMappings/read 读取任何存储分类映射
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/replicationStorageClassificationMappings/write 创建或更新任何存储分类映射
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/replicationStorageClassificationMappings/delete 删除任何存储分类映射
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/replicationStorageClassificationMappings/operationresults/read 跟踪对资源“存储分类映射”执行的异步操作的结果
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationvCenters/read 读取任何 vCenter
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationvCenters/write 创建或更新任何 vCenter
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationvCenters/delete 删除任何 vCenter
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationvCenters/operationresults/read 跟踪对资源“vCenters”执行的异步操作的结果
Microsoft.RecoveryServices/vaults/replicationJobs/read 读取任何作业
Microsoft.RecoveryServices/vaults/replicationJobs/cancel/action 取消作业
Microsoft.RecoveryServices/vaults/replicationJobs/restart/action 重新启动作业
Microsoft.RecoveryServices/vaults/replicationJobs/resume/action 恢复作业
Microsoft.RecoveryServices/vaults/replicationJobs/operationresults/read 跟踪对资源“作业”执行的异步操作的结果
Microsoft.RecoveryServices/vaults/replicationMigrationItems/read 读取任何迁移项
Microsoft.RecoveryServices/vaults/replicationNetworkMappings/read 读取任何网络映射
Microsoft.RecoveryServices/vaults/replicationNetworks/read 读取任何网络
Microsoft.RecoveryServices/vaults/replicationOperationStatus/read 读取任何保管库复制操作状态
Microsoft.RecoveryServices/vaults/replicationPolicies/read 读取任何策略
Microsoft.RecoveryServices/vaults/replicationPolicies/write 创建或更新任何策略
Microsoft.RecoveryServices/vaults/replicationPolicies/delete 删除任何策略
Microsoft.RecoveryServices/vaults/replicationPolicies/operationresults/read 跟踪对资源“策略”执行的异步操作的结果
Microsoft.RecoveryServices/vaults/replicationProtectedItems/read 读取任何受保护项
Microsoft.RecoveryServices/vaults/replicationProtectionContainerMappings/read 读取任何保护容器映射
Microsoft.RecoveryServices/vaults/replicationProtectionContainers/read 读取任何保护容器
Microsoft.RecoveryServices/vaults/replicationProtectionIntents/read 读取任何内容
Microsoft.RecoveryServices/vaults/replicationProtectionIntents/write 创建或更新任何
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/read 读取任何恢复计划
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/write 创建或更新任何恢复计划
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/delete 删除任何恢复计划
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/plannedFailover/action 计划内故障转移恢复计划
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/unplannedFailover/action 故障转移恢复计划
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/testFailover/action 测试故障转移恢复计划
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/testFailoverCleanup/action 测试故障转移清理恢复计划
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/failoverCommit/action 故障转移提交恢复计划
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/reProtect/action 重新保护恢复计划
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/failoverCancel/action 取消故障转移恢复计划
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/operationresults/read 跟踪对资源“恢复计划”执行的异步操作的结果
Microsoft.RecoveryServices/vaults/replicationRecoveryServicesProviders/read 读取任何恢复服务提供程序
Microsoft.RecoveryServices/vaults/replicationStorageClassificationMappings/read 读取任何存储分类映射
Microsoft.RecoveryServices/vaults/replicationStorageClassifications/read 读取任何存储分类
Microsoft.RecoveryServices/vaults/replicationSupportedOperatingSystems/read 读取任何内容
Microsoft.RecoveryServices/vaults/replicationSupportedRegionMappings/read 读取任何内容
Microsoft.RecoveryServices/vaults/replicationUsages/read 读取任何保管库复制使用情况
Microsoft.RecoveryServices/vaults/replicationVaultHealth/read 读取任何保管库复制运行状况
Microsoft.RecoveryServices/vaults/replicationVaultHealth/refresh/action 刷新保管库运行状况
Microsoft.RecoveryServices/vaults/replicationVaultHealth/operationresults/read 跟踪对资源“保管库复制运行状况”执行的异步操作的结果
Microsoft.RecoveryServices/vaults/replicationVaultSettings/read 读取任何内容
Microsoft.RecoveryServices/vaults/replicationVaultSettings/write 创建或更新任何
Microsoft.RecoveryServices/vaults/replicationvCenters/read 读取任何 vCenter
Microsoft.RecoveryServices/Vaults/usages/read 返回恢复服务保管库的使用情况详细信息。
Microsoft.RecoveryServices/vaults/usages/read 读取任何保管库使用情况
Microsoft.RecoveryServices/Vaults/vaultTokens/read “保管库令牌”操作可用于获取保管库级后端操作的保管库令牌。

Microsoft.ResourceGraph

可大规模查询、浏览和分析云资源的功能强大的工具。

Azure 服务:Azure Resource Graph

操作 说明
Microsoft.ResourceGraph/operations/read 获取支持的操作列表
Microsoft.ResourceGraph/queries/read 获取指定的图形查询
Microsoft.ResourceGraph/queries/delete 删除指定的图形查询
Microsoft.ResourceGraph/queries/write 创建/更新指定的图形查询
Microsoft.ResourceGraph/resourceChangeDetails/read 获取指定的资源更改的详细信息
Microsoft.ResourceGraph/resourceChanges/read 列出给定时间间隔的资源更改
Microsoft.ResourceGraph/resources/read 提交对指定订阅、管理组或租户范围内的资源的查询
Microsoft.ResourceGraph/resourcesHistory/read 列出指定订阅、管理组或租户范围内的资源历史记录的所有快照

Microsoft.ResourceHealth

诊断影响 Azure 资源的服务问题并获取相关支持。

Azure 服务:Azure 服务运行状况

操作 说明
Microsoft.ResourceHealth/events/action 用于提取事件详细信息的终结点
Microsoft.ResourceHealth/register/action 注册 Microsoft ResourceHealth 的订阅
Microsoft.ResourceHealth/unregister/action 取消注册 Microsoft ResourceHealth 的订阅
Microsoft.Resourcehealth/healthevent/action 表示指定资源的运行状况状态的更改
Microsoft.ResourceHealth/AvailabilityStatuses/read 获取指定范围内所有资源的可用性状态
Microsoft.ResourceHealth/AvailabilityStatuses/current/read 获取指定资源的可用性状态
Microsoft.ResourceHealth/emergingissues/read 获取 Azure 服务新出现的问题
Microsoft.ResourceHealth/events/read 获取给定订阅的服务运行状况事件
Microsoft.ResourceHealth/events/fetchEventDetails/action 用于提取事件详细信息的终结点
Microsoft.ResourceHealth/events/listSecurityAdvisoryImpactedResources/action 获取 SecurityAdvisory 类型的给定事件的受影响资源
Microsoft.ResourceHealth/events/impactedResources/read 获取给定事件的受影响资源
Microsoft.Resourcehealth/healthevent/Activated/action 表示指定资源的运行状况状态的更改
Microsoft.Resourcehealth/healthevent/Updated/action 表示指定资源的运行状况状态的更改
Microsoft.Resourcehealth/healthevent/Resolved/action 表示指定资源的运行状况状态的更改
Microsoft.Resourcehealth/healthevent/InProgress/action 表示指定资源的运行状况状态的更改
Microsoft.Resourcehealth/healthevent/Pending/action 表示指定资源的运行状况状态的更改
Microsoft.ResourceHealth/impactedResources/read 获取给定订阅中受影响的资源
Microsoft.ResourceHealth/metadata/read 获取元数据
Microsoft.ResourceHealth/Notifications/read 接收 Azure 资源管理器通知
Microsoft.ResourceHealth/Operations/read 获取可用于 Microsoft ResourceHealth 的操作
Microsoft.ResourceHealth/potentialoutages/read 获取给定订阅的潜在中断

Microsoft.Resources

适用于 Azure 的部署和管理服务,可用于在 Azure 订阅中创建、更新和删除资源。

Azure 服务:Azure Resource Manager

操作 说明
Microsoft.Resources/checkResourceName/action 检查资源名称的有效性。
Microsoft.Resources/calculateTemplateHash/action 计算所提供模板的哈希。
Microsoft.Resources/checkZonePeers/action 检查区域对等
Microsoft.Resources/changes/read 获取或列出更改
Microsoft.Resources/checkPolicyCompliance/read 参照资源策略检查给定资源的符合性状态。
Microsoft.Resources/deployments/read 获取或列出部署。
Microsoft.Resources/deployments/write 创建或更新部署。
Microsoft.Resources/deployments/delete 删除部署。
Microsoft.Resources/deployments/cancel/action 取消部署。
Microsoft.Resources/deployments/validate/action 验证部署。
Microsoft.Resources/deployments/whatIf/action 预测模板部署更改。
Microsoft.Resources/deployments/exportTemplate/action 导出部署的模板
Microsoft.Resources/deployments/operations/read 获取或列出部署操作。
Microsoft.Resources/deployments/operationstatuses/read 获取或列出部署操作状态。
Microsoft.Resources/deploymentScripts/read 获取或列出部署脚本
Microsoft.Resources/deploymentScripts/write 创建或更新部署脚本
Microsoft.Resources/deploymentScripts/delete 删除部署脚本
Microsoft.Resources/deploymentScripts/logs/read 获取或列出部署脚本日志
Microsoft.Resources/deploymentStacks/read 获取或列出部署堆栈
Microsoft.Resources/deploymentStacks/write 创建或更新部署堆栈
Microsoft.Resources/deploymentStacks/delete 删除部署堆栈
Microsoft.Resources/links/read 获取或列出资源链接。
Microsoft.Resources/links/write 创建或更新资源链接。
Microsoft.Resources/links/delete 删除资源链接。
Microsoft.Resources/locations/moboOperationStatuses/read 读取资源的 Mobo 服务操作状态。
Microsoft.Resources/marketplace/purchase/action 从市场购买资源。
Microsoft.Resources/moboBrokers/read 获取或列出 mobo 中转站
Microsoft.Resources/moboBrokers/write 创建或更新 mobo 中转站
Microsoft.Resources/moboBrokers/delete 删除 mobo 中转站
Microsoft.Resources/providers/read 获取提供程序的列表。
Microsoft.Resources/resources/read 基于筛选器获取资源的列表。
Microsoft.Resources/subscriptionRegistrations/read 获取资源提供程序命名空间的订阅注册。
Microsoft.Resources/subscriptions/read 获取订阅的列表。
Microsoft.Resources/subscriptions/locations/read 获取支持的位置列表。
Microsoft.Resources/subscriptions/operationresults/read 获取订阅操作结果。
Microsoft.Resources/subscriptions/providers/read 获取或列出资源提供程序。
Microsoft.Resources/subscriptions/resourceGroups/read 获取或列出资源组。
Microsoft.Resources/subscriptions/resourceGroups/write 创建或更新资源组。
Microsoft.Resources/subscriptions/resourceGroups/delete 删除资源组及其所有资源。
Microsoft.Resources/subscriptions/resourceGroups/moveResources/action 将资源从一个资源组移到另一个资源组。
Microsoft.Resources/subscriptions/resourceGroups/validateMoveResources/action 验证是否已将资源从一个资源组移到另一个资源组。
Microsoft.Resources/subscriptions/resourcegroups/deployments/read 获取或列出部署。
Microsoft.Resources/subscriptions/resourcegroups/deployments/write 创建或更新部署。
Microsoft.Resources/subscriptions/resourcegroups/deployments/operations/read 获取或列出部署操作。
Microsoft.Resources/subscriptions/resourcegroups/deployments/operationstatuses/read 获取或列出部署操作状态。
Microsoft.Resources/subscriptions/resourcegroups/resources/read 获取资源组的资源。
Microsoft.Resources/subscriptions/resources/read 获取订阅的资源。
Microsoft.Resources/subscriptions/tagNames/read 获取或列出订阅标记。
Microsoft.Resources/subscriptions/tagNames/write 添加订阅标记。
Microsoft.Resources/subscriptions/tagNames/delete 删除订阅标记。
Microsoft.Resources/subscriptions/tagNames/tagValues/read 获取或列出订阅标记值。
Microsoft.Resources/subscriptions/tagNames/tagValues/write 添加订阅标记值。
Microsoft.Resources/subscriptions/tagNames/tagValues/delete 删除订阅标记值。
Microsoft.Resources/tags/read 获取资源上的所有标记。
Microsoft.Resources/tags/write 更新资源上的标记,方法是:替换现有标记或将其与新的标记组合并,或者删除现有标记。
Microsoft.Resources/tags/delete 删除资源上的所有标记。
Microsoft.Resources/templateSpecs/read 获取或列出模板规格
Microsoft.Resources/templateSpecs/write 创建或更新模板规格
Microsoft.Resources/templateSpecs/delete 删除模板规格
Microsoft.Resources/templateSpecs/versions/read 获取或列出模板规格
Microsoft.Resources/templateSpecs/versions/write 创建或更新模板规格版本
Microsoft.Resources/templateSpecs/versions/delete 删除模板规格版本
Microsoft.Resources/tenants/read 获取租户的列表。

Microsoft.Solutions

找到可满足应用程序或业务需求的解决方案。

Azure 服务:Azure 托管应用程序

操作 说明
Microsoft.Solutions/register/action 注册 Microsoft.Solutions 的订阅
Microsoft.Solutions/unregister/action 取消注册 Microsoft.Solutions 的订阅
Microsoft.Solutions/applicationDefinitions/read 获取托管应用程序定义。
Microsoft.Solutions/applicationDefinitions/write 创建或更新托管应用程序定义。
Microsoft.Solutions/applicationDefinitions/delete 删除托管应用程序定义。
Microsoft.Solutions/applicationDefinitions/write 更新托管应用程序定义。
Microsoft.Solutions/applicationDefinitions/read 列出资源组中的托管应用程序定义。
Microsoft.Solutions/applicationDefinitions/read 列出订阅中的所有应用程序定义。
Microsoft.Solutions/applications/read 获取托管应用程序。
Microsoft.Solutions/applications/write 创建或更新托管应用程序。
Microsoft.Solutions/applications/delete 删除托管应用程序。
Microsoft.Solutions/applications/write 更新现有的托管应用程序。
Microsoft.Solutions/applications/read 列出资源组中的所有应用程序。
Microsoft.Solutions/applications/read 列出订阅中的所有应用程序。
Microsoft.Solutions/applications/refreshPermissions/action 刷新应用程序的权限。
Microsoft.Solutions/applications/listAllowedUpgradePlans/action 列出应用程序的允许升级计划。
Microsoft.Solutions/applications/updateAccess/action 更新应用程序的访问。
Microsoft.Solutions/applications/listTokens/action 列出应用程序的令牌。
Microsoft.Solutions/jitRequests/read 获取 JIT 请求。
Microsoft.Solutions/jitRequests/write 创建或更新 JIT 请求。
Microsoft.Solutions/jitRequests/delete 删除 JIT 请求。
Microsoft.Solutions/jitRequests/write 更新 JIT 请求。
Microsoft.Solutions/jitRequests/read 列出订阅中的所有 JIT 请求。
Microsoft.Solutions/jitRequests/read 列出资源组中的所有 JIT 请求。
Microsoft.Solutions/locations/operationstatuses/read 读取 operationstatuses
Microsoft.Solutions/locations/operationstatuses/write 写入 operationstatuses
Microsoft.Solutions/operations/read 读取操作

后续步骤