Azure Containers built-in role

Defender Kubernetes API Access

Grants Microsoft Defender for Cloud access to Azure Kubernetes Services

Control-plane and data-plane permissions below are imported directly from Microsoft Learn. In-app editorial guidance (use cases, best practices, security notes) and least-privilege recommendations are still pending review.

Role definition ID: d5a2ae44-610b-4500-93be-660a0c5f5ca6

Control-plane actions (11)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Official Microsoft Learn documentation →