Custom Roles (Start Here)¶
TRiA supports a large number of Microsoft Azure services and adds services regularly. To access these services, we recommend using either a read-only role or a power-user role.
If you are interested in operating in a read-only fashion, which will prevent TRiA from taking actions against your Microsoft Azure resources, then we recommend using the TRiA Standard User role.
If you would like to use TRiA to manage your Microsoft Azure resources directly or through the use of Bots, then use the TRiA Power User role.
TRiA Standard User Role¶
{
"Name": "TRiA Standard User",
"Id": null,
"IsCustom": true,
"Description": "Provides read-only access to resources supported by TRiA.",
"Actions": [
"Microsoft.Authorization/*/read",
"Microsoft.Cache/redis/read",
"Microsoft.Compute/disks/read",
"Microsoft.Compute/images/read",
"Microsoft.Compute/locations/*/read",
"Microsoft.Compute/skus/read",
"Microsoft.Compute/snapshots/read",
"Microsoft.Compute/virtualMachines/*/read",
"Microsoft.DBforMySQL/locations/performanceTiers/read",
"Microsoft.DBforMySQL/performanceTiers/read",
"Microsoft.DBforMySQL/servers/configurations/read",
"Microsoft.DBforMySQL/servers/firewallRules/read",
"Microsoft.DBforMySQL/servers/read",
"Microsoft.DBforMySQL/servers/virtualNetworkRules/read",
"Microsoft.DBforPostgreSQL/locations/performanceTiers/read",
"Microsoft.DBforPostgreSQL/performanceTiers/read",
"Microsoft.DBforPostgreSQL/servers/configurations/read",
"Microsoft.DBforPostgreSQL/servers/firewallRules/read",
"Microsoft.DBforPostgreSQL/servers/read",
"Microsoft.DBforPostgreSQL/servers/virtualNetworkRules/read",
"Microsoft.DocumentDB/databaseAccounts/read",
"Microsoft.DocumentDB/databaseAccounts/usages/read",
"Microsoft.HDInsight/*/read",
"Microsoft.Insights/LogProfiles/read",
"Microsoft.Network/dnszones/*/read",
"Microsoft.Network/locations/usages/read",
"Microsoft.Network/networkInterfaces/*/read",
"Microsoft.Network/networkSecurityGroups/*/read",
"Microsoft.Network/networkSecurityGroups/*/read",
"Microsoft.Network/publicIPAddresses/*/read",
"Microsoft.Network/virtualNetworks/*/read",
"Microsoft.Resources/subscriptions/read",
"Microsoft.Security/policies/read",
"Microsoft.Sql/servers/administrators/read",
"Microsoft.Sql/servers/auditingSettings/read",
"Microsoft.Sql/servers/databases/auditingSettings/read",
"Microsoft.Sql/servers/databases/read",
"Microsoft.Sql/servers/databases/securityAlertPolicies/read",
"Microsoft.Sql/servers/databases/skus/read",
"Microsoft.Sql/servers/databases/transparentDataEncryption/read",
"Microsoft.Sql/servers/firewallRules/read",
"Microsoft.Sql/servers/read",
"Microsoft.Sql/servers/securityAlertPolicies/read",
"Microsoft.Sql/servers/virtualNetworkRules/read",
"Microsoft.Storage/storageAccounts/blobServices/containers/read",
"Microsoft.Storage/storageAccounts/read",
"Microsoft.Support/read",
"Microsoft.Advisor/recommendations/read",
"Microsoft.DBforMariaDB/locations/performanceTiers/read",
"Microsoft.DBforMariaDB/performanceTiers/read",
"Microsoft.DBforMariaDB/servers/configurations/read",
"Microsoft.DBforMariaDB/servers/firewallRules/read",
"Microsoft.DBforMariaDB/servers/read",
"Microsoft.DBforMariaDB/servers/virtualNetworkRules/read",
"Microsoft.KeyVault/vaults/read",
"Microsoft.Network/expressRouteCircuits/*/read",
"Microsoft.Network/loadBalancers/*/read",
"Microsoft.Network/routeTables/*/read",
"Microsoft.Security/*/read"
],
"NotActions": [
],
"AssignableScopes": [
"/subscriptions/00000000-0000-0000-0000-000000000000",
"/subscriptions/11111111-1111-1111-1111-111111111111"
]
}
TRiA Power User Role¶
{
"Name": "TRiA Power User",
"Id": null,
"IsCustom": true,
"Description": "Provides full access to resources supported by TRiA.",
"Actions": [
"Microsoft.Authorization/*",
"Microsoft.Cache/*",
"Microsoft.Compute/*",
"Microsoft.DBforMySQL/*",
"Microsoft.DBforPostgreSQL/*",
"Microsoft.DocumentDB/*",
"Microsoft.HDInsight/*",
"Microsoft.Insights/*",
"Microsoft.Network/*",
"Microsoft.Resources/*",
"Microsoft.Security/*",
"Microsoft.Sql/*",
"Microsoft.Storage/*",
"Microsoft.Support/*",
"Microsoft.Advisor/*",
"Microsoft.DBforMariaDB/*",
"Microsoft.KeyVault/*"
],
"NotActions": [
],
"AssignableScopes": [
"/subscriptions/00000000-0000-0000-0000-000000000000",
"/subscriptions/11111111-1111-1111-1111-111111111111"
]
}
Creating Custom Roles¶
To add one of these roles to your account, copy the JSON from one of the desired roles above into a file and use either PowerShell or Azure CLI from the command line to create the role.
PowerShell
New-AzureRmRoleDefinition -InputFile <role_definition>
Azure CLI
az role definition create --role-definition <role_definition>
Updating Custom Roles¶
To modify an existing custom role:
Retrieve the existing role with either PowerShell or Azure CLI.
PowerShell
Get-AzureRmRoleDefinition -Custom | ConvertTo-JsonAzure CLI
az role definition list --custom-role-onlyCopy the JSON for the custom role you wish to modify into a new file and make the desired changes to the role definition. Then update the role in Azure.
PowerShell
Set-AzureRmRoleDefinition -InputFile <role_definition>Azure CLI
az role definition update --role-definition <role_definition>