Azure Containers built-in role
Defender Kubernetes API Access
Grants Microsoft Defender for Cloud access to Azure Kubernetes Services
Control-plane and data-plane permissions below are imported directly from Microsoft Learn. In-app editorial guidance (use cases, best practices, security notes) and least-privilege recommendations are still pending review.
Role definition ID: d5a2ae44-610b-4500-93be-660a0c5f5ca6
Control-plane actions (11)
Microsoft.ContainerService/managedClusters/trustedAccessRoleBindings/writeMicrosoft.ContainerService/managedClusters/trustedAccessRoleBindings/readMicrosoft.ContainerService/managedClusters/trustedAccessRoleBindings/deleteMicrosoft.ContainerService/managedClusters/readMicrosoft.Features/features/readMicrosoft.Features/providers/features/readMicrosoft.Features/providers/features/register/actionMicrosoft.Security/pricings/securityoperators/readMicrosoft.Security/securityOperators/readMicrosoft.Authorization/policyAssignments/readMicrosoft.Authorization/policySetDefinitions/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/