Custom Roles (Start Here) ========================= TRiA supports a large number of Microsoft Azure services and adds services regularly. To access these services, we recommend using either a read-only role or a power-user role. If you are interested in operating in a read-only fashion, which will prevent TRiA from taking actions against your Microsoft Azure resources, then we recommend using the TRiA Standard User role. If you would like to use TRiA to manage your Microsoft Azure resources directly or through the use of Bots, then use the TRiA Power User role. .. _skim: ../../release_notes.html TRiA Standard User Role ----------------------------- .. literalinclude:: /examples/policies/azure_readonly.txt :language: json TRiA Power User Role -------------------------- .. literalinclude:: /examples/policies/azure_poweruser.txt :language: json Creating Custom Roles --------------------- To add one of these roles to your account, copy the JSON from one of the desired roles above into a file and use either PowerShell or Azure CLI from the command line to create the role. **PowerShell** .. code-block:: powershell New-AzureRmRoleDefinition -InputFile **Azure CLI** .. code-block:: bash az role definition create --role-definition Updating Custom Roles --------------------- To modify an existing custom role: Retrieve the existing role with either PowerShell or Azure CLI. **PowerShell** .. code-block:: powershell Get-AzureRmRoleDefinition -Custom | ConvertTo-Json **Azure CLI** .. code-block:: bash az role definition list --custom-role-only Copy the JSON for the custom role you wish to modify into a new file and make the desired changes to the role definition. Then update the role in Azure. **PowerShell** .. code-block:: powershell Set-AzureRmRoleDefinition -InputFile **Azure CLI** .. code-block:: bash az role definition update --role-definition