Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| azure:azure_iam [2025/09/24 14:44] – [Security Principles] mmuze | azure:azure_iam [2025/10/02 20:52] (current) – [Working With Roles] mmuze | ||
|---|---|---|---|
| Line 72: | Line 72: | ||
| * [[https:// | * [[https:// | ||
| * [[https:// | * [[https:// | ||
| - | |||
| - | ====== Related ====== | ||
| - | * [[azure: | ||
| - | * [[azure: | ||
| ====== Roles ====== | ====== Roles ====== | ||
| Line 83: | Line 79: | ||
| >The User Access Administrator role grants the ability to view all resources and manage access assignments at any subscription or management group level within the tenant. Due to its high privilege level, this role assignment should be removed immediately after completing the necessary changes at the root scope to minimize security risks. | >The User Access Administrator role grants the ability to view all resources and manage access assignments at any subscription or management group level within the tenant. Due to its high privilege level, this role assignment should be removed immediately after completing the necessary changes at the root scope to minimize security risks. | ||
| + | |||
| + | ====== Working With Roles ====== | ||
| + | |||
| + | Get the Azure Roles assigned to a user. | ||
| + | < | ||
| + | Get-AzRoleAssignment -SigninName " | ||
| + | </ | ||
| + | |||
| + | < | ||
| + | az role assignment list --assignee " | ||
| + | </ | ||
| + | |||
| + | === Get Roles that have a permission === | ||
| + | |||
| + | < | ||
| + | Get-AzRoleDefinition | Where-Object { | ||
| + | $_.Actions -match " | ||
| + | } | ||
| + | </ | ||
| + | ====== Related ====== | ||
| + | * [[azure: | ||
| + | * [[azure: | ||