# Azure permission mapping

| Category                              | Entity create level        | Tessell Permission                                                              | Cloud Description                                                                                          | Applicable for Register Use Case(Not completely managed Tessell Sub) | Feature Mapping                                                                                | Private CP DP Use Case               |
| ------------------------------------- | -------------------------- | ------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ------------------------------------ |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/blobServices/read                             | Grants read access to blob services within storage accounts.                                               | Yes                                                                  | Subscription                                                                                   | <p>Private CP DP<br>Public CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/blobServices/write                            | <p>Allows updating settings of blob services within storage<br>accounts.</p>                               | Yes                                                                  | Subscription                                                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/blobServices/containers/blobs/\*              | <p>Grants all permissions on blobs within containers in blob<br>services of storage accounts.</p>          | Yes                                                                  | PITR                                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/blobServices/containers/blobs/add/action      | Allows adding new blobs to containers.                                                                     | Yes                                                                  | PITR                                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete          | Grants permission to delete blobs within containers.                                                       | Yes                                                                  | SLA                                                                                            | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/blobServices/containers/blobs/move/action     | Allows moving blobs between containers or within a container.                                              | Yes                                                                  | PITR,DAP                                                                                       | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read            | Grants read access to blobs within containers.                                                             | <p>Yes<br></p>                                                       | PITR,Clone                                                                                     | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/blobServices/containers/blobs/write           | Allows writing or updating blobs within containers.                                                        | <p>Yes<br></p>                                                       | PITR                                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/listkeys/action                               | Allows listing the access keys for a storage account.                                                      | <p>Yes<br></p>                                                       | PITR                                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/checknameavailability/read                                    | Allows checking the availability of a storage account name.                                                | Yes                                                                  | PITR                                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/read                                          | Grants read access to storage accounts                                                                     | <p>Yes<br></p>                                                       | Subscription,PITR                                                                              | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/write                                         | Allows creating or updating storage accounts.                                                              | <p>No<br></p>                                                        | Subscription,PITR                                                                              | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/delete                                        | Grants permission to delete storage accounts.                                                              | <p>No<br></p>                                                        | Delete AM                                                                                      | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/locations/checknameavailability/read                          | <p>Allows checking storage account name availability in specific<br>locations.</p>                         | <p>Yes<br></p>                                                       | PITR                                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/operations/read                                               | Grants read access to storage account operations metadata.                                                 | <p>Yes<br></p>                                                       | PITR,Clone                                                                                     | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/objectReplicationPolicies/write               | Allows creating or updating object replication policies for storage accounts.                              | Yes                                                                  | DAP                                                                                            | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/objectReplicationPolicies/read                | Grants read access to object replication policies within storage accounts.                                 | Yes                                                                  | DAP                                                                                            | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/objectReplicationPolicies/delete              | <p>Grants permission to delete object replication policies within<br>storage accounts.</p>                 | Yes                                                                  | DAP                                                                                            | <p>Public CP DP<br>Private CP DP</p> |
| Compute Operations                    |                            | Microsoft.Compute/locations/operations/read                                     | Grants read access to compute operations in specific locations.                                            | Yes                                                                  | <p>Provisioning,Add Instance,Clone,Restore,Service<br>Resize</p>                               | <p>Public CP DP<br>Private CP DP</p> |
| Data Collection Endpoints             | Region                     | Microsoft.Insights/DataCollectionEndpoints/Write                                | Allows creating or updating data collection endpoints.                                                     | Yes                                                                  | Subscription, DB Logs                                                                          | <p>Public CP DP<br>Private CP DP</p> |
| Data Collection Endpoints             | Region                     | Microsoft.Insights/DataCollectionEndpoints/Read                                 | Grants read access to data collection endpoints.                                                           | Yes                                                                  | <p>Subscription,Provisioning,Add<br>Instance,Clone,Restore, DB Logs</p>                        | <p>Public CP DP<br>Private CP DP</p> |
| Data Collection Endpoints             | Region                     | Microsoft.Insights/DataCollectionEndpoints/Delete                               | Grants permission to delete data collection endpoints.                                                     | <p>Yes<br></p>                                                       | Subscription,DB Logs                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Data Collection Rules                 | <p>Compute<br>Resource</p> | Microsoft.Insights/dataCollectionRuleAssociations/Write                         | Allows creating or updating data collection rule associations.                                             | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore, DB Logs                                               | <p>Public CP DP<br>Private CP DP</p> |
| Data Collection Rules                 | <p>Compute<br>Resource</p> | Microsoft.Insights/dataCollectionRuleAssociations/Read                          | Grants read access to data collection rule associations.                                                   | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore, DB Logs                                               | <p>Public CP DP<br>Private CP DP</p> |
| Data Collection Rules                 | <p>Compute<br>Resource</p> | Microsoft.Insights/dataCollectionRuleAssociations/Delete                        | Grants permission to delete data collection rule associations.                                             | <p>Yes<br></p>                                                       | Delete Service,DB Logs                                                                         | <p>Public CP DP<br>Private CP DP</p> |
| Data Collection Rules                 | <p>Compute<br>Resource</p> | Microsoft.Insights/dataCollectionRules/write                                    | Allows creating or updating data collection rules.                                                         | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore,DB Logs                                                | <p>Public CP DP<br>Private CP DP</p> |
| Data Collection Rules                 | <p>Compute<br>Resource</p> | Microsoft.Insights/dataCollectionRules/read                                     | Grants read access to data collection rules.                                                               | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore, DB Logs                                               | <p>Public CP DP<br>Private CP DP</p> |
| Data Collection Rules                 | <p>Compute<br>Resource</p> | Microsoft.Insights/dataCollectionRules/Delete                                   | Grants permission to delete data collection rules.                                                         | <p>Yes<br></p>                                                       | Delete Service,DB Logs                                                                         | <p>Public CP DP<br>Private CP DP</p> |
| Disk Encryption Sets                  | Region                     | Microsoft.Compute/diskEncryptionSets/read                                       | Grants read access to disk encryption sets.                                                                | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Disk Encryption Sets                  | Region                     | Microsoft.Compute/diskEncryptionSets/write                                      | Allows creating or updating disk encryption sets.                                                          | <p>No<br></p>                                                        | Provisioning,Add Instance,Clone,Restore-BYOK                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Disk Encryption Sets                  | Region                     | Microsoft.Compute/diskEncryptionSets/delete                                     | Grants permission to delete disk encryption sets.                                                          | <p>No<br></p>                                                        | Provisioning,Add Instance,Clone,Restore-BYOK                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Disks                                 | DB Service                 | Microsoft.Compute/disks/read                                                    | Grants read access to disks.                                                                               | <p>Yes<br></p>                                                       | <p>Provisioning,Add<br>Instance,Clone,Restore,Patching,Resize</p>                              | <p>Public CP DP<br>Private CP DP</p> |
| Disks                                 | DB Service                 | Microsoft.Compute/disks/write                                                   | Allows creating or updating disks.                                                                         | <p>Yes<br></p>                                                       | <p>Provisioning,Add<br>Instance,Clone,Restore,Patching,Resize</p>                              | <p>Public CP DP<br>Private CP DP</p> |
| Disks                                 | DB Service                 | Microsoft.Compute/disks/delete                                                  | Grants permission to delete disks.                                                                         | Yes                                                                  | Delete Service, Delete Instance, Patching                                                      | <p>Public CP DP<br>Private CP DP</p> |
| Disks                                 | DB Service                 | Microsoft.Compute/disks/beginGetAccess/action                                   | Initiates access to a disk.                                                                                | Yes                                                                  | <p>Provisioning,Add<br>Instance,Clone,Restore,Patching,Resize</p>                              | <p>Public CP DP<br>Private CP DP</p> |
| Disks                                 | DB Service                 | Microsoft.Compute/disks/endGetAccess/action                                     | Revokes access toa disk.                                                                                   | Yes                                                                  | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Disks                                 | DB Service                 | Microsoft.Compute/disks/download/action                                         | Allows downloading disks.                                                                                  | Yes                                                                  |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Disks                                 | DB Service                 | Microsoft.Compute/disks/upload/action                                           | Allows uploading data to disks.                                                                            | Yes                                                                  |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/accessPolicies/write                                  | Allows creating or updating access policies for a Key Vault.                                               | No                                                                   | Subscription                                                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/deploy/action                                         | Allows deploying resources into a Key Vault.                                                               | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/versions/read                                    | Grants read access to all versions of a key in a Key Vault.                                                | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/read                                             | Grants read access to keys stored in a Key Vault.                                                          | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/write                                            | Allows creating or updating keys in a Key Vault.                                                           | <p>No<br></p>                                                        | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/encrypt/action                                   | Allows encrypting data using keys stored in the Key Vault.                                                 | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/decrypt/action                                   | Allows decrypting data using keys stored in the Key Vault.                                                 | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/create/action                                    | Allows creating new keys in the Key Vault.                                                                 | <p>No<br></p>                                                        | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/update/action                                    | Allows updating existing keys in the Key Vault.                                                            | <p>No<br></p>                                                        | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/delete                                           | Grants permmission to delete keys from the Key Vault.                                                      | <p>No<br></p>                                                        | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/purge/action                                     | Allows purging deleted keys from the Key Vault permanently.                                                | No                                                                   | Delete Service,Delete Instance                                                                 | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/import/action                                    | Allows importing keys into the Key Vault.                                                                  | <p>No<br></p>                                                        | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/ocations/operationResults/read                               | <p>Grants read access to the results of Key Vault operations in<br>specific locations.</p>                 | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/operations/read                                              | Grants read access to Key Vault operations metadata.                                                       | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/secrets/write                                         | Allows creating or updating secrets in a Key Vault.                                                        | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CPDP<br>Private CP DP</p>  |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/secrets/delete                                        | Grants permission to delete secrets from the Key Vault.                                                    | Yes                                                                  | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/secrets/getSecret/action                              | Allows retrieving (reading) secrets from the Key Vault.                                                    | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/secrets/update/action                                 | Allows updating secrets in the Key Vault.                                                                  | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/secrets/purge/action                                  | Allows purging deleted secrets from the Key Vault permanently.                                             | Yes                                                                  | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/secrets/setSecret/action                              | Allows setting (creating or updating) secrets in the Key Vault.                                            | Yes                                                                  | Change Password                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/read                                                  | Grants read access to Key Vaults.                                                                          | Yes                                                                  |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/write                                                 | Allows creating or updating Key Vaults.                                                                    | No                                                                   |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/delete                                                | Grants permission to delete Key Vaults.                                                                    | <p>No<br></p>                                                        |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Load Balancer                         | VPC                        | Microsoft.Network/loadBalancers/backendAddressPools/write                       | <p>Allows creating or updating backend address pools of load<br>balancers.</p>                             | Yes                                                                  |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Load Balancer                         | VPC                        | Microsoft.Network/loadBalancers/backendAddressPools/read                        | Grants read access to backend address pools of load balanoers.                                             | Yes                                                                  |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Load Balancer                         | VPC                        | Microsoft.Network/loadBalancers/backendAddressPools/delete                      | <p>Grants permission to delete backend address pools of load<br>balancers.</p>                             | Yes                                                                  |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Load Balancer                         | VPC                        | Microsoft.Network/loadBalancers/backendAddressPools/join/action                 | Allows backend pools to be associated with other resources.                                                | Yes                                                                  |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Load Balancer                         | VPC                        | Microsoft.Network/loadBalancers/read                                            | Grants read access to load balancers.                                                                      | Yes                                                                  | Create Private Link                                                                            | <p>Public CP DP<br>Private CP DP</p> |
| Load Balancer                         | VPC                        | Microsoft.Network/loadBalancers/write                                           | Allows creating or updating load balancers.                                                                | Yes                                                                  | Create Private Link                                                                            | <p>Public CP DP<br>Private CP DP</p> |
| Load Balancer                         | VPC                        | Microsoft.Network/loadBalancers/delete                                          | Grants permission to delete load balancers.                                                                | Yes                                                                  | Create Private Link                                                                            | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.Operationallnsights/workspaces/datasources/write                      | <p>Allows creating or updating data sources in a Log Analytics<br>workspace.</p>                           | Yes                                                                  | Provisioning,Add Instance,Clone,Restore, DB Logs                                               | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.Operationallnsights/locations/operationstatuses/read                  | <p>Grants read access to operation statuses of Log Analytics in<br>specific locations.</p>                 | Yes                                                                  | <p>Subscription, Provisioning,Add<br>Instance,Clone,Restore, DB Logs</p>                       | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.OperationalInsights/workspaces/tables/query/read                      | <p>Grants read access to queries on tables in a Log Analytics<br>workspace.</p>                            | Yes                                                                  | DB Logs                                                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.Operationallnsights/workspaces/tables/write                           | Allows creating or updating tables in a Log Analytics workspace.                                           | Yes                                                                  | Subscription,DB Logs                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.Operationallnsights/workspaces/tables/read                            | Grants read access to tables in a Log Analytics workspace.                                                 | Yes                                                                  | Subscription,DB Logs                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.Operationallnsights/workspaces/tables/delete                          | Grants permission to delete tables in a Log Analytics workspace.                                           | Yes                                                                  | Subscription,DB Logs                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.Operationallnsights/workspaces/query/"/read                           | Grants read access to all queries in a Log Analytics workspace.                                            | Yes                                                                  | DB Logs                                                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.Operationallnsights/workspaces/read                                   | Grants read access to Log Analytics workspaces.                                                            | Yes                                                                  | Subscription, DB Logs                                                                          | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.Operationallnsights/workspaces/sharedkeys/action                      | Allows access to shared keys of a Log Analytics workspace.                                                 | Yes                                                                  | Subscription,DB Logs                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.Operationallnsights/workspaces/delete                                 | Grants permission to delete Log Analytics workspaces.                                                      | No                                                                   | Subscription,DB Logs                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| NAT Gateway                           | VPC                        | Microsoft.Network/natGateways/write                                             | Allows creating or updating NAT gateways.                                                                  | Yes                                                                  | <p>Update Service access from Public to<br>Private(Non-BYON)</p>                               | Public CP DP                         |
| NAT Gateway                           | VPC                        | Microsoft.Network/natGateways/delete                                            | Grants permission to delete NAT gateways.                                                                  | Yes                                                                  | <p>Update Service access from Public to<br>Private(Non-BYON)</p>                               | Public CP DP                         |
| NAT Gateway                           | VPC                        | Microsoft.Network/natGateways/read                                              | Grants read access to NAT gateways.                                                                        | <p>Yes<br></p>                                                       | <p>Update Service access from Public to<br>Private(Non-BYON)</p>                               | Public CP DP                         |
| NAT Gateway                           | VPC                        | Microsoft.Network/natGateways/join/action                                       | Allows NAT gateways to be associated with other resources.                                                 | <p>Yes<br></p>                                                       | <p>Update Service access from Public to<br>Private(Non-BYON)</p>                               | Public CP DP                         |
| Network Interface                     | <p>Compute<br>Resource</p> | Microsoft.Network/networkinterfaces/read                                        | Grants read access to network interfaces.                                                                  | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Network Interface                     | <p>Compute<br>Resource</p> | Microsoft.Network/networkInterfaces/write                                       | Allows creating or updating network interfaces.                                                            | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Network Interface                     | <p>Compute<br>Resource</p> | Microsoft.Network/networkinterfaces/delete                                      | Grants permission to delete network interfaces.                                                            | <p>Yes<br></p>                                                       | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Network Interface                     | <p>Compute<br>Resource</p> | Microsoft.Network/networkinterfaces/join/action                                 | Allows network interfaces to be associated with other resources.                                           | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Network Security Group                | DB Service                 | Microsoft.Network/networkSecurityGroups/securityRules/read                      | <p>Grants read access to security rules within network security<br>groups.</p>                             | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Network Security Group                | DB Service                 | Microsoft.Network/networkSecurityGroups/securityRules/write                     | Allows creating or updating security rules within network security groups.                                 | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Network Security Group                | DB Service                 | Microsoft.Network/networkSecurityGroups/securityRules/delete                    | <p>Grants permission to delete security rules within network<br>security groups.</p>                       | Yes                                                                  | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Network Security Group                | DB Service                 | Microsoft.Network/networkSecurityGroups/read                                    | Grants read access to network security groups (NSGs).                                                      | Yes                                                                  | Provisioning.Add Instance,Clone,Restore,Add IPs                                                | <p>Public CP DP<br>Private CP DP</p> |
| Network Security Group                | DB Service                 | Microsoft.Network/networkSecurityGroups/write                                   | Allows creating or updating network security groups.                                                       | Yes                                                                  | Provisioning,Add Instance,Clone,Restore,Add IPs                                                | <p>Public CP DP<br>Private CP DP</p> |
| Network Security Group                | DB Service                 | Microsoft.Network/networkSecurityGroups/delete                                  | Grants permission to delete network security groups.                                                       | Yes                                                                  | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Network Security Group                | DB Service                 | Microsoft.Network/networkSecurityGroups/join/action                             | Allows NSGs to be associated with other resources.                                                         | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Network/privateLinkServices/privateEndpointConnections/read           | Grants read access to private endpoint connections associated with a private link service.                 | Yes                                                                  | Subscription,Service Private Link                                                              | <p>Public CP DP<br>Private CP DP</p> |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Network/privateLinkServices/privateEndpointConnections/write          | Allows updating private endpoint connections associated with a private link service.                       | Yes                                                                  | Create Service Private Link                                                                    | <p>Public CP DP<br>Private CP DP</p> |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Network/privateLinkServices/privateEndpointConnections/delete         | <p>Grants permission to delete private endpoint connections<br>associated with a private link service.</p> | Yes                                                                  | Delete Service Private Link                                                                    | <p>Public CP DP<br>Private CP DP</p> |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Network/privateLinkServices/PrivateEndpointConnectionsApproval/action | Allows approving private endpoint connections to a private link service.                                   | Yes                                                                  | Subscription                                                                                   | Private CP DP                        |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Network/privateLinkServices/notifyPrivateEndpointMove/action          | <p>Allows notifying about private endpoint moves related to a<br>private link service.</p>                 | Yes                                                                  | Subscription                                                                                   | Private CP DP                        |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Network/privateEndpoints/read                                         | Grants read access to private endpoints.                                                                   | Yes                                                                  | Subscription                                                                                   | Private CP DP                        |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Insights/PrivateLinkScopes/ScopedResources/Read                       | Grants read access to resources scoped within a Private Link Scope.                                        | Yes                                                                  | Subscription                                                                                   | Private CP DP                        |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Insights/PrivateLinkScopes/ScopedResources/Write                      | <p>Allows adding or updating resources scoped within a Private<br>Link Scope.</p>                          | Yes                                                                  | Subscription                                                                                   | Private CP DP                        |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Insights/PrivateLinkScopes/ScopedResources/Delete                     | Grants permission to delete resources scoped within a Private Link Scope.                                  | Yes                                                                  | Subscription                                                                                   | Private CP DP                        |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Insights/privateLinkScopes/read                                       | Grants read access to Azure Monitor Private Link Scopes.                                                   | Yes                                                                  | Subscription                                                                                   | Private CP DP                        |
| Private Link Services                 | VPC                        | Microsoft.Network/locations/autoApprovedPrivateLinkServices/read                | <p>Grants read access to auto-approved private link services in<br>specific locations.</p>                 | Yes                                                                  | Create Service Private Link                                                                    | <p>Private CP DP<br>Public CP DP</p> |
| Private Link Services                 | VPC                        | Microsoft.Network/locations/availablePrivateEndpointTypes/read                  | <p>Grants read access to available private endpoint types in<br>specific locations.</p>                    | Yes                                                                  | Create Service Private Link                                                                    | <p>Private CP DP<br>Public CP DP</p> |
| Private Link Services                 | VPC                        | Microsoft.Network/privateLinkServices/read                                      | Grants read access to private link services.                                                               | Yes                                                                  | Private Link                                                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Private Link Services                 | VPC                        | Microsoft.Network/privateLinkServices/write                                     | Allows creating or updating private link services.                                                         | Yes                                                                  | Create Service Private Link                                                                    | <p>Public CP DP<br>Private CP DP</p> |
| Private Link Services                 | VPC                        | Microsoft.Network/privateLinkServices/delete                                    | Grants permission to delete private link services.                                                         | <p>Yes<br></p>                                                       | Delete Service Private Link                                                                    | <p>Public CP DP<br>Private CP DP</p> |
| Public IP Address                     | <p>Compute<br>Resource</p> | Microsoft.Network/publiclPAddresses/read                                        | Grants read access to public IP addresses.                                                                 | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Public IP Address                     | <p>Compute<br>Resource</p> | Microsoft.Network/publiclPAddresses/write                                       | Allows creating or updating public IP addresses.                                                           | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Public IP Address                     | <p>Compute<br>Resource</p> | Microsoft.Network/publiclPAddresses/delete                                      | Grants permission to delete public IP addresses.                                                           | Yes                                                                  | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Public IP Address                     | <p>Compute<br>Resource</p> | Microsoft.Network/publiclPAddresses/join/action                                 | <p>Allows public IP addresses to be associated with other<br>resources.</p>                                | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Resource Groups                       |                            | Microsoft.Resources/subscriptions/resourceGroups/read                           | Grants read access to resource groups within a subscription.                                               | Yes                                                                  | Subscription                                                                                   | <p>Public CP DP<br>Private CPDP</p>  |
| Resource Locks                        | <p>Compute<br>Resource</p> | Microsoft.Authorization/locks/read                                              | Grants read access to resource locks.                                                                      | Yes                                                                  | <p>Provisioning,Add Instance,Clone,Restore, Start<br>Service, Stop Service, Delete Service</p> | <p>Public CP DP<br>Private CP DP</p> |
| Resource Locks                        | <p>Compute<br>Resource</p> | Microsoft.Authorization/locks/write                                             | Allows creating or updating resource locks.                                                                | Yes                                                                  | <p>Provisioning,Add Instance,Clone,Restore, Start<br>Service,Stop Service, Delete Service</p>  | <p>Public CP DP<br>Private CP DP</p> |
| Resource Locks                        | <p>Compute<br>Resource</p> | Microsoft.Authorization/locks/delete                                            | Grants permission to delete resource locks.                                                                | Yes                                                                  | Stop Service, Delete Service                                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Role Assignments                      |                            | Microsoft.Authorization/roleAssignments/read                                    | Grants read access to role assignments.                                                                    | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Run Commands                          |                            | Microsoft.Compute/virtualMachines/runCommands/write                             | Allows creating or updating run commands on virtual machines.                                              | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CPDP</p>  |
| <p>Shared Image Gallery<br>Images</p> |                            | Microsoft.Compute/galleries/images/versions/read                                | Grants read access to image versions in shared image galleries.                                            | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| <p>Shared Image Gallery<br>Images</p> |                            | Microsoft.Compute/galleries/images/versions/write                               | <p>Allows creating or updating image versions in shared image<br>galleries.</p>                            | <p>Yes<br></p>                                                       |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| <p>Shared Image Gallery<br>Images</p> |                            | Microsoft.Compute/galleries/images/versions/delete                              | <p>Grants permission to delete image versions in shared image<br>galleries.</p>                            | <p>Yes<br></p>                                                       |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Snapshots                             | DB Service                 | Microsoft.Compute/snapshots/write                                               | Allows creating or updating snapshots of disks.                                                            | Yes                                                                  | AM                                                                                             | <p>Public CP DP<br>Private CP DP</p> |
| Snapshots                             | DB Service                 | Microsoft.Compute/snapshots/delete                                              | Grants permission to delete disk snapshots.                                                                | <p>Yes<br></p>                                                       | AM                                                                                             | <p>Public CP DP<br>Private CP DP</p> |
| Snapshots                             | DB Service                 | Microsoft.Compute/snapshots/beginGetAccess/action                               | Initiates access to a snapshot.                                                                            | <p>Yes<br></p>                                                       | AM                                                                                             | <p>Public CP DP<br>Private CP DP</p> |
| Snapshots                             | DB Service                 | Microsoft.Compute/snapshots/endGetAccess/action                                 | Revokes access to a snapshot.                                                                              | Yes                                                                  | AM                                                                                             | <p>Public CP DP<br>Private CP DP</p> |
| Snapshots                             | DB Service                 | Microsoft.Compute/snapshots/read                                                | Grants read access to disk snapshots.                                                                      | Yes                                                                  | Clone,Restore                                                                                  | <p>Public CP DP<br>Private CP DP</p> |
| Snapshots                             | DB Service                 | Microsoft.Compute/snapshots/download/action                                     | Allows downloading snapshots.                                                                              | Yes                                                                  |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Snapshots                             | DB Service                 | Microsoft.Compute/snapshots/upload/action                                       | Allows uploading data to snapshots.                                                                        | Yes                                                                  |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Managed Identity                      | <p>Resource<br>Group</p>   | Microsoft.Managedldentity/userAssignedldentities/read                           | Grants read access to user-assigned managed identities.                                                    | Yes                                                                  | Subscription, Provisioning.Add Instance,Clone,Restore                                          | <p>Public CP DP<br>Private CP DP</p> |
| Managed Identity                      | <p>Resource<br>Group</p>   | Microsoft.Managedldentity/userAssignedldentities/assign/action                  | <p>Allows assigning a user-assigned managed identity to a<br>resource.</p>                                 | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Machines                      | <p>Compute<br>Resource</p> | Microsoft.Compute/virtualMachines/read                                          | Grants read access to virtual machines (VMs).                                                              | <p>Yes<br></p>                                                       | <p>Provisioning,Add Instance,Clone,Restore,Stop<br>Service,Start Service</p>                   | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Machines                      | <p>Compute<br>Resource</p> | Microsoft.Compute/virtualMachines/write                                         | Allows creating or updating virtual machines.                                                              | <p>Yes<br></p>                                                       | <p>Provisioning,Add Instance,Clone,Restore,Stop<br>Service,Start Service</p>                   | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Machines                      | <p>Compute<br>Resource</p> | Microsoft.Compute/virtualMachines/delete                                        | Grants permission to delete virtual machines.                                                              | <p>Yes<br></p>                                                       | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Machines                      | <p>Compute<br>Resource</p> | Microsoft.Compute/virtualMachines/start/action                                  | Allows starting a virtual machine.                                                                         | <p>Yes<br></p>                                                       | Start Service                                                                                  | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Machines                      | <p>Compute<br>Resource</p> | Microsoft.Compute/virtualMachines/powerOff/action                               | Allows powering off a virtual machine.                                                                     | <p>Yes<br></p>                                                       | Stop Service                                                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Machines                      | <p>Compute<br>Resource</p> | Microsoft.Compute/virtualMachines/restart/action                                | Allows restarting a virtual machine.                                                                       | <p>Yes<br></p>                                                       |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Machines                      | <p>Compute<br>Resource</p> | Microsoft.Compute/virtualMachines/runCommand/action                             | Allows running commands on a virtual machine remotely.                                                     | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Machines                      | <p>Compute<br>Resource</p> | Microsoft.Compute/virtualMachines/deallocate/action                             | Allows deallocating a virtual machine.                                                                     | <p>Yes<br></p>                                                       | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Network Peerings              | VPC                        | Microsoft.Network/virtualNetworks/virtualNetworkPeerings/read                   | Grants read access to virtual network peerings.                                                            | <p>No<br></p>                                                        | Add Instance                                                                                   | <p>Public CPDP<br>Private CP DP</p>  |
| Virtual Network Peerings              | VPC                        | Microsoft.Network/virtualNetworks/virtualNetworkPeerings/write                  | Allows creating or updating virtual network peerings.                                                      | <p>No<br></p>                                                        | Add Instance                                                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Network Peerings              | VPC                        | Microsoft.Network/virtualNetworks/virtualNetworkPeerings/delete                 | Grants permission to delete virtual network peerings.                                                      | <p>No<br></p>                                                        | Add Instance                                                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Networks                      | VPC                        | Microsoft.Network/virtualNetworks/read                                          | Grants read access to virtual networks.                                                                    | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Networks                      | VPC                        | Microsoft.Network/virtualNetworks/write                                         | Allows creating or updating virtual networks.                                                              | No                                                                   | Add Network                                                                                    | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Networks                      | VPC                        | Microsoft.Network/virtualNetworks/delete                                        | Grants permission to delete virtual networks.                                                              | <p>No<br></p>                                                        | Remove Network                                                                                 | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Networks                      | VPC                        | Microsoft.Network/virtualNetworks/peer/action                                   | Allows peering of virtual networks.                                                                        | <p>No<br></p>                                                        | Add Instance                                                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Networks                      | VPC                        | Microsoft.Network/virtualNetworks/subnets/read                                  | Grants read access to subnets within a virtual network.                                                    | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Networks                      | VPC                        | Microsoft.Network/virtualNetworks/subnets/join/action                           | Allows subnets to be associated with other resources.                                                      | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Networks                      | VPC                        | Microsoft.Network/virtualNetworks/subnets/write                                 | Allows creating or updating subnets within a virtual network.                                              | <p>No<br></p>                                                        | Add Network                                                                                    | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Networks                      | VPC                        | Microsoft.Network/virtualNetworks/subnets/delete                                | Grants permission to delete subnets within a virtual network.                                              | No                                                                   | Remove Network                                                                                 | <p>Public CP DP<br>Private CP DP</p> |
| VM Evtensi                            |                            | Microsoft.Compute/virtualMachines/extensions/write                              | Allows adding or updating extensions on virtual machines.                                                  | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| VM Extensions                         |                            | Microsoft.Compute/virtualMachines/extensions/read                               | Grants read access to virtual machine extensions.                                                          | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.tessell.com/tessell/governance/subscriptions/azure-permission-mapping.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
