Azure sql auditing scripts and new cosmos role for _pim_cosmos_ users #98329 #98330 #98328 #98681

This commit is contained in:
Jurjen Ladenius
2024-04-11 14:38:26 +02:00
parent 3df9ea6d44
commit c91b0f0908
4 changed files with 1468 additions and 0 deletions

View File

@@ -0,0 +1,22 @@
{
"id": "/providers/Microsoft.Authorization/roleDefinitions/01032560-a033-4a7e-977d-c360b71b9217",
"properties": {
"roleName": "Cosmos DB List Keys",
"description": "Lets you list keys for Azure Cosmos DB accounts. Used for PIM cosmos roles.",
"assignableScopes": [
"/providers/Microsoft.Management/managementGroups/e9792fd7-4044-47e7-a40d-3fba46f1cd09"
],
"permissions": [
{
"actions": [
"Microsoft.DocumentDB/databaseAccounts/readonlyKeys/*",
"Microsoft.DocumentDB/databaseAccounts/listKeys/*",
"Microsoft.DocumentDB/databaseAccounts/listConnectionStrings/*"
],
"notActions": [],
"dataActions": [],
"notDataActions": []
}
]
}
}