Azure Management and governance built-in role
Azure Center for SAP solutions service role
Azure Center for SAP solutions service role - This role is intended to be used for providing the permissions to user assigned managed identity. Azure Center for SAP solutions will use this identity to deploy and manage SAP systems.
Control-plane and data-plane permissions below are imported directly from Microsoft Learn. In-app editorial guidance (use cases, best practices, security notes) and least-privilege recommendations are still pending review.
Role definition ID: aabbc5dd-1af0-458b-a942-81af88f9c138
Control-plane actions (55)
Microsoft.Resources/subscriptions/resourceGroups/writeMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/*Microsoft.Network/loadBalancers/readMicrosoft.Network/loadBalancers/writeMicrosoft.Network/loadBalancers/backendAddressPools/readMicrosoft.Network/loadBalancers/backendAddressPools/writeMicrosoft.Network/loadBalancers/frontendIPConfigurations/readMicrosoft.Network/loadBalancers/loadBalancingRules/readMicrosoft.Network/loadBalancers/inboundNatRules/readMicrosoft.Network/loadBalancers/providers/Microsoft.Insights/logDefinitions/readMicrosoft.Network/loadBalancers/networkInterfaces/readMicrosoft.Network/loadBalancers/outboundRules/readMicrosoft.Network/loadBalancers/virtualMachines/readMicrosoft.Network/loadBalancers/providers/Microsoft.Insights/metricDefinitions/readMicrosoft.Network/networkInterfaces/readMicrosoft.Network/networkInterfaces/writeMicrosoft.Network/networkInterfaces/ipconfigurations/readMicrosoft.Network/networkInterfaces/loadBalancers/readMicrosoft.Network/virtualNetworks/readMicrosoft.Network/virtualNetworks/checkIpAddressAvailability/readMicrosoft.Network/virtualNetworks/subnets/readMicrosoft.Network/virtualNetworks/subnets/virtualMachines/readMicrosoft.Network/virtualNetworks/virtualMachines/readMicrosoft.Network/networkInterfaces/ipconfigurations/join/actionMicrosoft.Network/privateEndpoints/readMicrosoft.Network/privateEndpoints/writeMicrosoft.Network/networkInterfaces/join/actionMicrosoft.Network/loadBalancers/backendAddressPools/join/actionMicrosoft.Network/loadBalancers/frontendIPConfigurations/join/actionMicrosoft.Network/virtualNetworks/subnets/join/actionMicrosoft.Network/virtualNetworks/subnets/joinLoadBalancer/actionMicrosoft.Storage/storageAccounts/readMicrosoft.Storage/storageAccounts/writeMicrosoft.Storage/storageAccounts/PrivateEndpointConnectionsApproval/actionMicrosoft.Storage/storageAccounts/blobServices/readMicrosoft.Storage/storageAccounts/blobServices/containers/readMicrosoft.Storage/storageAccounts/fileServices/readMicrosoft.Storage/storageAccounts/fileServices/writeMicrosoft.Storage/storageAccounts/fileServices/shares/readMicrosoft.Storage/storageAccounts/fileServices/shares/writeMicrosoft.Compute/virtualMachines/readMicrosoft.Compute/virtualMachines/writeMicrosoft.Compute/virtualMachines/instanceView/readMicrosoft.Compute/availabilitySets/readMicrosoft.Compute/availabilitySets/writeMicrosoft.Compute/skus/readMicrosoft.Compute/sshPublicKeys/readMicrosoft.Compute/virtualMachines/extensions/readMicrosoft.Compute/virtualMachines/extensions/writeMicrosoft.Compute/virtualMachines/extensions/deleteMicrosoft.Compute/disks/readMicrosoft.Compute/disks/write
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/