# Azure permission mapping

| Category                              | Entity create level        | Tessell Permission                                                              | Cloud Description                                                                                          | Applicable for Register Use Case(Not completely managed Tessell Sub) | Feature Mapping                                                                                | Private CP DP Use Case               |
| ------------------------------------- | -------------------------- | ------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ------------------------------------ |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/blobServices/read                             | Grants read access to blob services within storage accounts.                                               | Yes                                                                  | Subscription                                                                                   | <p>Private CP DP<br>Public CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/blobServices/write                            | <p>Allows updating settings of blob services within storage<br>accounts.</p>                               | Yes                                                                  | Subscription                                                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/blobServices/containers/blobs/\*              | <p>Grants all permissions on blobs within containers in blob<br>services of storage accounts.</p>          | Yes                                                                  | PITR                                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/blobServices/containers/blobs/add/action      | Allows adding new blobs to containers.                                                                     | Yes                                                                  | PITR                                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete          | Grants permission to delete blobs within containers.                                                       | Yes                                                                  | SLA                                                                                            | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/blobServices/containers/blobs/move/action     | Allows moving blobs between containers or within a container.                                              | Yes                                                                  | PITR,DAP                                                                                       | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read            | Grants read access to blobs within containers.                                                             | <p>Yes<br></p>                                                       | PITR,Clone                                                                                     | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/blobServices/containers/blobs/write           | Allows writing or updating blobs within containers.                                                        | <p>Yes<br></p>                                                       | PITR                                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/listkeys/action                               | Allows listing the access keys for a storage account.                                                      | <p>Yes<br></p>                                                       | PITR                                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/checknameavailability/read                                    | Allows checking the availability of a storage account name.                                                | Yes                                                                  | PITR                                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/read                                          | Grants read access to storage accounts                                                                     | <p>Yes<br></p>                                                       | Subscription,PITR                                                                              | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/write                                         | Allows creating or updating storage accounts.                                                              | <p>No<br></p>                                                        | Subscription,PITR                                                                              | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/delete                                        | Grants permission to delete storage accounts.                                                              | <p>No<br></p>                                                        | Delete AM                                                                                      | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/locations/checknameavailability/read                          | <p>Allows checking storage account name availability in specific<br>locations.</p>                         | <p>Yes<br></p>                                                       | PITR                                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/operations/read                                               | Grants read access to storage account operations metadata.                                                 | <p>Yes<br></p>                                                       | PITR,Clone                                                                                     | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/objectReplicationPolicies/write               | Allows creating or updating object replication policies for storage accounts.                              | Yes                                                                  | DAP                                                                                            | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/objectReplicationPolicies/read                | Grants read access to object replication policies within storage accounts.                                 | Yes                                                                  | DAP                                                                                            | <p>Public CP DP<br>Private CP DP</p> |
| Storage Account                       | Region                     | Microsoft.Storage/storageAccounts/objectReplicationPolicies/delete              | <p>Grants permission to delete object replication policies within<br>storage accounts.</p>                 | Yes                                                                  | DAP                                                                                            | <p>Public CP DP<br>Private CP DP</p> |
| Compute Operations                    |                            | Microsoft.Compute/locations/operations/read                                     | Grants read access to compute operations in specific locations.                                            | Yes                                                                  | <p>Provisioning,Add Instance,Clone,Restore,Service<br>Resize</p>                               | <p>Public CP DP<br>Private CP DP</p> |
| Data Collection Endpoints             | Region                     | Microsoft.Insights/DataCollectionEndpoints/Write                                | Allows creating or updating data collection endpoints.                                                     | Yes                                                                  | Subscription, DB Logs                                                                          | <p>Public CP DP<br>Private CP DP</p> |
| Data Collection Endpoints             | Region                     | Microsoft.Insights/DataCollectionEndpoints/Read                                 | Grants read access to data collection endpoints.                                                           | Yes                                                                  | <p>Subscription,Provisioning,Add<br>Instance,Clone,Restore, DB Logs</p>                        | <p>Public CP DP<br>Private CP DP</p> |
| Data Collection Endpoints             | Region                     | Microsoft.Insights/DataCollectionEndpoints/Delete                               | Grants permission to delete data collection endpoints.                                                     | <p>Yes<br></p>                                                       | Subscription,DB Logs                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Data Collection Rules                 | <p>Compute<br>Resource</p> | Microsoft.Insights/dataCollectionRuleAssociations/Write                         | Allows creating or updating data collection rule associations.                                             | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore, DB Logs                                               | <p>Public CP DP<br>Private CP DP</p> |
| Data Collection Rules                 | <p>Compute<br>Resource</p> | Microsoft.Insights/dataCollectionRuleAssociations/Read                          | Grants read access to data collection rule associations.                                                   | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore, DB Logs                                               | <p>Public CP DP<br>Private CP DP</p> |
| Data Collection Rules                 | <p>Compute<br>Resource</p> | Microsoft.Insights/dataCollectionRuleAssociations/Delete                        | Grants permission to delete data collection rule associations.                                             | <p>Yes<br></p>                                                       | Delete Service,DB Logs                                                                         | <p>Public CP DP<br>Private CP DP</p> |
| Data Collection Rules                 | <p>Compute<br>Resource</p> | Microsoft.Insights/dataCollectionRules/write                                    | Allows creating or updating data collection rules.                                                         | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore,DB Logs                                                | <p>Public CP DP<br>Private CP DP</p> |
| Data Collection Rules                 | <p>Compute<br>Resource</p> | Microsoft.Insights/dataCollectionRules/read                                     | Grants read access to data collection rules.                                                               | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore, DB Logs                                               | <p>Public CP DP<br>Private CP DP</p> |
| Data Collection Rules                 | <p>Compute<br>Resource</p> | Microsoft.Insights/dataCollectionRules/Delete                                   | Grants permission to delete data collection rules.                                                         | <p>Yes<br></p>                                                       | Delete Service,DB Logs                                                                         | <p>Public CP DP<br>Private CP DP</p> |
| Disk Encryption Sets                  | Region                     | Microsoft.Compute/diskEncryptionSets/read                                       | Grants read access to disk encryption sets.                                                                | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Disk Encryption Sets                  | Region                     | Microsoft.Compute/diskEncryptionSets/write                                      | Allows creating or updating disk encryption sets.                                                          | <p>No<br></p>                                                        | Provisioning,Add Instance,Clone,Restore-BYOK                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Disk Encryption Sets                  | Region                     | Microsoft.Compute/diskEncryptionSets/delete                                     | Grants permission to delete disk encryption sets.                                                          | <p>No<br></p>                                                        | Provisioning,Add Instance,Clone,Restore-BYOK                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Disks                                 | DB Service                 | Microsoft.Compute/disks/read                                                    | Grants read access to disks.                                                                               | <p>Yes<br></p>                                                       | <p>Provisioning,Add<br>Instance,Clone,Restore,Patching,Resize</p>                              | <p>Public CP DP<br>Private CP DP</p> |
| Disks                                 | DB Service                 | Microsoft.Compute/disks/write                                                   | Allows creating or updating disks.                                                                         | <p>Yes<br></p>                                                       | <p>Provisioning,Add<br>Instance,Clone,Restore,Patching,Resize</p>                              | <p>Public CP DP<br>Private CP DP</p> |
| Disks                                 | DB Service                 | Microsoft.Compute/disks/delete                                                  | Grants permission to delete disks.                                                                         | Yes                                                                  | Delete Service, Delete Instance, Patching                                                      | <p>Public CP DP<br>Private CP DP</p> |
| Disks                                 | DB Service                 | Microsoft.Compute/disks/beginGetAccess/action                                   | Initiates access to a disk.                                                                                | Yes                                                                  | <p>Provisioning,Add<br>Instance,Clone,Restore,Patching,Resize</p>                              | <p>Public CP DP<br>Private CP DP</p> |
| Disks                                 | DB Service                 | Microsoft.Compute/disks/endGetAccess/action                                     | Revokes access toa disk.                                                                                   | Yes                                                                  | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Disks                                 | DB Service                 | Microsoft.Compute/disks/download/action                                         | Allows downloading disks.                                                                                  | Yes                                                                  |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Disks                                 | DB Service                 | Microsoft.Compute/disks/upload/action                                           | Allows uploading data to disks.                                                                            | Yes                                                                  |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/accessPolicies/write                                  | Allows creating or updating access policies for a Key Vault.                                               | No                                                                   | Subscription                                                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/deploy/action                                         | Allows deploying resources into a Key Vault.                                                               | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/versions/read                                    | Grants read access to all versions of a key in a Key Vault.                                                | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/read                                             | Grants read access to keys stored in a Key Vault.                                                          | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/write                                            | Allows creating or updating keys in a Key Vault.                                                           | <p>No<br></p>                                                        | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/encrypt/action                                   | Allows encrypting data using keys stored in the Key Vault.                                                 | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/decrypt/action                                   | Allows decrypting data using keys stored in the Key Vault.                                                 | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/create/action                                    | Allows creating new keys in the Key Vault.                                                                 | <p>No<br></p>                                                        | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/update/action                                    | Allows updating existing keys in the Key Vault.                                                            | <p>No<br></p>                                                        | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/delete                                           | Grants permmission to delete keys from the Key Vault.                                                      | <p>No<br></p>                                                        | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/purge/action                                     | Allows purging deleted keys from the Key Vault permanently.                                                | No                                                                   | Delete Service,Delete Instance                                                                 | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/keys/import/action                                    | Allows importing keys into the Key Vault.                                                                  | <p>No<br></p>                                                        | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/ocations/operationResults/read                               | <p>Grants read access to the results of Key Vault operations in<br>specific locations.</p>                 | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/operations/read                                              | Grants read access to Key Vault operations metadata.                                                       | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/secrets/write                                         | Allows creating or updating secrets in a Key Vault.                                                        | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CPDP<br>Private CP DP</p>  |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/secrets/delete                                        | Grants permission to delete secrets from the Key Vault.                                                    | Yes                                                                  | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/secrets/getSecret/action                              | Allows retrieving (reading) secrets from the Key Vault.                                                    | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/secrets/update/action                                 | Allows updating secrets in the Key Vault.                                                                  | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/secrets/purge/action                                  | Allows purging deleted secrets from the Key Vault permanently.                                             | Yes                                                                  | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/secrets/setSecret/action                              | Allows setting (creating or updating) secrets in the Key Vault.                                            | Yes                                                                  | Change Password                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/read                                                  | Grants read access to Key Vaults.                                                                          | Yes                                                                  |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/write                                                 | Allows creating or updating Key Vaults.                                                                    | No                                                                   |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Key Vault                             | Region                     | Microsoft.KeyVault/vaults/delete                                                | Grants permission to delete Key Vaults.                                                                    | <p>No<br></p>                                                        |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Load Balancer                         | VPC                        | Microsoft.Network/loadBalancers/backendAddressPools/write                       | <p>Allows creating or updating backend address pools of load<br>balancers.</p>                             | Yes                                                                  |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Load Balancer                         | VPC                        | Microsoft.Network/loadBalancers/backendAddressPools/read                        | Grants read access to backend address pools of load balanoers.                                             | Yes                                                                  |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Load Balancer                         | VPC                        | Microsoft.Network/loadBalancers/backendAddressPools/delete                      | <p>Grants permission to delete backend address pools of load<br>balancers.</p>                             | Yes                                                                  |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Load Balancer                         | VPC                        | Microsoft.Network/loadBalancers/backendAddressPools/join/action                 | Allows backend pools to be associated with other resources.                                                | Yes                                                                  |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Load Balancer                         | VPC                        | Microsoft.Network/loadBalancers/read                                            | Grants read access to load balancers.                                                                      | Yes                                                                  | Create Private Link                                                                            | <p>Public CP DP<br>Private CP DP</p> |
| Load Balancer                         | VPC                        | Microsoft.Network/loadBalancers/write                                           | Allows creating or updating load balancers.                                                                | Yes                                                                  | Create Private Link                                                                            | <p>Public CP DP<br>Private CP DP</p> |
| Load Balancer                         | VPC                        | Microsoft.Network/loadBalancers/delete                                          | Grants permission to delete load balancers.                                                                | Yes                                                                  | Create Private Link                                                                            | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.Operationallnsights/workspaces/datasources/write                      | <p>Allows creating or updating data sources in a Log Analytics<br>workspace.</p>                           | Yes                                                                  | Provisioning,Add Instance,Clone,Restore, DB Logs                                               | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.Operationallnsights/locations/operationstatuses/read                  | <p>Grants read access to operation statuses of Log Analytics in<br>specific locations.</p>                 | Yes                                                                  | <p>Subscription, Provisioning,Add<br>Instance,Clone,Restore, DB Logs</p>                       | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.OperationalInsights/workspaces/tables/query/read                      | <p>Grants read access to queries on tables in a Log Analytics<br>workspace.</p>                            | Yes                                                                  | DB Logs                                                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.Operationallnsights/workspaces/tables/write                           | Allows creating or updating tables in a Log Analytics workspace.                                           | Yes                                                                  | Subscription,DB Logs                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.Operationallnsights/workspaces/tables/read                            | Grants read access to tables in a Log Analytics workspace.                                                 | Yes                                                                  | Subscription,DB Logs                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.Operationallnsights/workspaces/tables/delete                          | Grants permission to delete tables in a Log Analytics workspace.                                           | Yes                                                                  | Subscription,DB Logs                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.Operationallnsights/workspaces/query/"/read                           | Grants read access to all queries in a Log Analytics workspace.                                            | Yes                                                                  | DB Logs                                                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.Operationallnsights/workspaces/read                                   | Grants read access to Log Analytics workspaces.                                                            | Yes                                                                  | Subscription, DB Logs                                                                          | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.Operationallnsights/workspaces/sharedkeys/action                      | Allows access to shared keys of a Log Analytics workspace.                                                 | Yes                                                                  | Subscription,DB Logs                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| Log Analytics Workspace               | <p>Resource<br>Group</p>   | Microsoft.Operationallnsights/workspaces/delete                                 | Grants permission to delete Log Analytics workspaces.                                                      | No                                                                   | Subscription,DB Logs                                                                           | <p>Public CP DP<br>Private CP DP</p> |
| NAT Gateway                           | VPC                        | Microsoft.Network/natGateways/write                                             | Allows creating or updating NAT gateways.                                                                  | Yes                                                                  | <p>Update Service access from Public to<br>Private(Non-BYON)</p>                               | Public CP DP                         |
| NAT Gateway                           | VPC                        | Microsoft.Network/natGateways/delete                                            | Grants permission to delete NAT gateways.                                                                  | Yes                                                                  | <p>Update Service access from Public to<br>Private(Non-BYON)</p>                               | Public CP DP                         |
| NAT Gateway                           | VPC                        | Microsoft.Network/natGateways/read                                              | Grants read access to NAT gateways.                                                                        | <p>Yes<br></p>                                                       | <p>Update Service access from Public to<br>Private(Non-BYON)</p>                               | Public CP DP                         |
| NAT Gateway                           | VPC                        | Microsoft.Network/natGateways/join/action                                       | Allows NAT gateways to be associated with other resources.                                                 | <p>Yes<br></p>                                                       | <p>Update Service access from Public to<br>Private(Non-BYON)</p>                               | Public CP DP                         |
| Network Interface                     | <p>Compute<br>Resource</p> | Microsoft.Network/networkinterfaces/read                                        | Grants read access to network interfaces.                                                                  | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Network Interface                     | <p>Compute<br>Resource</p> | Microsoft.Network/networkInterfaces/write                                       | Allows creating or updating network interfaces.                                                            | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Network Interface                     | <p>Compute<br>Resource</p> | Microsoft.Network/networkinterfaces/delete                                      | Grants permission to delete network interfaces.                                                            | <p>Yes<br></p>                                                       | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Network Interface                     | <p>Compute<br>Resource</p> | Microsoft.Network/networkinterfaces/join/action                                 | Allows network interfaces to be associated with other resources.                                           | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Network Security Group                | DB Service                 | Microsoft.Network/networkSecurityGroups/securityRules/read                      | <p>Grants read access to security rules within network security<br>groups.</p>                             | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Network Security Group                | DB Service                 | Microsoft.Network/networkSecurityGroups/securityRules/write                     | Allows creating or updating security rules within network security groups.                                 | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Network Security Group                | DB Service                 | Microsoft.Network/networkSecurityGroups/securityRules/delete                    | <p>Grants permission to delete security rules within network<br>security groups.</p>                       | Yes                                                                  | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Network Security Group                | DB Service                 | Microsoft.Network/networkSecurityGroups/read                                    | Grants read access to network security groups (NSGs).                                                      | Yes                                                                  | Provisioning.Add Instance,Clone,Restore,Add IPs                                                | <p>Public CP DP<br>Private CP DP</p> |
| Network Security Group                | DB Service                 | Microsoft.Network/networkSecurityGroups/write                                   | Allows creating or updating network security groups.                                                       | Yes                                                                  | Provisioning,Add Instance,Clone,Restore,Add IPs                                                | <p>Public CP DP<br>Private CP DP</p> |
| Network Security Group                | DB Service                 | Microsoft.Network/networkSecurityGroups/delete                                  | Grants permission to delete network security groups.                                                       | Yes                                                                  | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Network Security Group                | DB Service                 | Microsoft.Network/networkSecurityGroups/join/action                             | Allows NSGs to be associated with other resources.                                                         | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Network/privateLinkServices/privateEndpointConnections/read           | Grants read access to private endpoint connections associated with a private link service.                 | Yes                                                                  | Subscription,Service Private Link                                                              | <p>Public CP DP<br>Private CP DP</p> |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Network/privateLinkServices/privateEndpointConnections/write          | Allows updating private endpoint connections associated with a private link service.                       | Yes                                                                  | Create Service Private Link                                                                    | <p>Public CP DP<br>Private CP DP</p> |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Network/privateLinkServices/privateEndpointConnections/delete         | <p>Grants permission to delete private endpoint connections<br>associated with a private link service.</p> | Yes                                                                  | Delete Service Private Link                                                                    | <p>Public CP DP<br>Private CP DP</p> |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Network/privateLinkServices/PrivateEndpointConnectionsApproval/action | Allows approving private endpoint connections to a private link service.                                   | Yes                                                                  | Subscription                                                                                   | Private CP DP                        |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Network/privateLinkServices/notifyPrivateEndpointMove/action          | <p>Allows notifying about private endpoint moves related to a<br>private link service.</p>                 | Yes                                                                  | Subscription                                                                                   | Private CP DP                        |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Network/privateEndpoints/read                                         | Grants read access to private endpoints.                                                                   | Yes                                                                  | Subscription                                                                                   | Private CP DP                        |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Insights/PrivateLinkScopes/ScopedResources/Read                       | Grants read access to resources scoped within a Private Link Scope.                                        | Yes                                                                  | Subscription                                                                                   | Private CP DP                        |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Insights/PrivateLinkScopes/ScopedResources/Write                      | <p>Allows adding or updating resources scoped within a Private<br>Link Scope.</p>                          | Yes                                                                  | Subscription                                                                                   | Private CP DP                        |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Insights/PrivateLinkScopes/ScopedResources/Delete                     | Grants permission to delete resources scoped within a Private Link Scope.                                  | Yes                                                                  | Subscription                                                                                   | Private CP DP                        |
| <p>Private Endpoint<br>Connection</p> | <p>Resource<br>Group</p>   | Microsoft.Insights/privateLinkScopes/read                                       | Grants read access to Azure Monitor Private Link Scopes.                                                   | Yes                                                                  | Subscription                                                                                   | Private CP DP                        |
| Private Link Services                 | VPC                        | Microsoft.Network/locations/autoApprovedPrivateLinkServices/read                | <p>Grants read access to auto-approved private link services in<br>specific locations.</p>                 | Yes                                                                  | Create Service Private Link                                                                    | <p>Private CP DP<br>Public CP DP</p> |
| Private Link Services                 | VPC                        | Microsoft.Network/locations/availablePrivateEndpointTypes/read                  | <p>Grants read access to available private endpoint types in<br>specific locations.</p>                    | Yes                                                                  | Create Service Private Link                                                                    | <p>Private CP DP<br>Public CP DP</p> |
| Private Link Services                 | VPC                        | Microsoft.Network/privateLinkServices/read                                      | Grants read access to private link services.                                                               | Yes                                                                  | Private Link                                                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Private Link Services                 | VPC                        | Microsoft.Network/privateLinkServices/write                                     | Allows creating or updating private link services.                                                         | Yes                                                                  | Create Service Private Link                                                                    | <p>Public CP DP<br>Private CP DP</p> |
| Private Link Services                 | VPC                        | Microsoft.Network/privateLinkServices/delete                                    | Grants permission to delete private link services.                                                         | <p>Yes<br></p>                                                       | Delete Service Private Link                                                                    | <p>Public CP DP<br>Private CP DP</p> |
| Public IP Address                     | <p>Compute<br>Resource</p> | Microsoft.Network/publiclPAddresses/read                                        | Grants read access to public IP addresses.                                                                 | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Public IP Address                     | <p>Compute<br>Resource</p> | Microsoft.Network/publiclPAddresses/write                                       | Allows creating or updating public IP addresses.                                                           | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Public IP Address                     | <p>Compute<br>Resource</p> | Microsoft.Network/publiclPAddresses/delete                                      | Grants permission to delete public IP addresses.                                                           | Yes                                                                  | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Public IP Address                     | <p>Compute<br>Resource</p> | Microsoft.Network/publiclPAddresses/join/action                                 | <p>Allows public IP addresses to be associated with other<br>resources.</p>                                | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Resource Groups                       |                            | Microsoft.Resources/subscriptions/resourceGroups/read                           | Grants read access to resource groups within a subscription.                                               | Yes                                                                  | Subscription                                                                                   | <p>Public CP DP<br>Private CPDP</p>  |
| Resource Locks                        | <p>Compute<br>Resource</p> | Microsoft.Authorization/locks/read                                              | Grants read access to resource locks.                                                                      | Yes                                                                  | <p>Provisioning,Add Instance,Clone,Restore, Start<br>Service, Stop Service, Delete Service</p> | <p>Public CP DP<br>Private CP DP</p> |
| Resource Locks                        | <p>Compute<br>Resource</p> | Microsoft.Authorization/locks/write                                             | Allows creating or updating resource locks.                                                                | Yes                                                                  | <p>Provisioning,Add Instance,Clone,Restore, Start<br>Service,Stop Service, Delete Service</p>  | <p>Public CP DP<br>Private CP DP</p> |
| Resource Locks                        | <p>Compute<br>Resource</p> | Microsoft.Authorization/locks/delete                                            | Grants permission to delete resource locks.                                                                | Yes                                                                  | Stop Service, Delete Service                                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Role Assignments                      |                            | Microsoft.Authorization/roleAssignments/read                                    | Grants read access to role assignments.                                                                    | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Run Commands                          |                            | Microsoft.Compute/virtualMachines/runCommands/write                             | Allows creating or updating run commands on virtual machines.                                              | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CPDP</p>  |
| <p>Shared Image Gallery<br>Images</p> |                            | Microsoft.Compute/galleries/images/versions/read                                | Grants read access to image versions in shared image galleries.                                            | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| <p>Shared Image Gallery<br>Images</p> |                            | Microsoft.Compute/galleries/images/versions/write                               | <p>Allows creating or updating image versions in shared image<br>galleries.</p>                            | <p>Yes<br></p>                                                       |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| <p>Shared Image Gallery<br>Images</p> |                            | Microsoft.Compute/galleries/images/versions/delete                              | <p>Grants permission to delete image versions in shared image<br>galleries.</p>                            | <p>Yes<br></p>                                                       |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Snapshots                             | DB Service                 | Microsoft.Compute/snapshots/write                                               | Allows creating or updating snapshots of disks.                                                            | Yes                                                                  | AM                                                                                             | <p>Public CP DP<br>Private CP DP</p> |
| Snapshots                             | DB Service                 | Microsoft.Compute/snapshots/delete                                              | Grants permission to delete disk snapshots.                                                                | <p>Yes<br></p>                                                       | AM                                                                                             | <p>Public CP DP<br>Private CP DP</p> |
| Snapshots                             | DB Service                 | Microsoft.Compute/snapshots/beginGetAccess/action                               | Initiates access to a snapshot.                                                                            | <p>Yes<br></p>                                                       | AM                                                                                             | <p>Public CP DP<br>Private CP DP</p> |
| Snapshots                             | DB Service                 | Microsoft.Compute/snapshots/endGetAccess/action                                 | Revokes access to a snapshot.                                                                              | Yes                                                                  | AM                                                                                             | <p>Public CP DP<br>Private CP DP</p> |
| Snapshots                             | DB Service                 | Microsoft.Compute/snapshots/read                                                | Grants read access to disk snapshots.                                                                      | Yes                                                                  | Clone,Restore                                                                                  | <p>Public CP DP<br>Private CP DP</p> |
| Snapshots                             | DB Service                 | Microsoft.Compute/snapshots/download/action                                     | Allows downloading snapshots.                                                                              | Yes                                                                  |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Snapshots                             | DB Service                 | Microsoft.Compute/snapshots/upload/action                                       | Allows uploading data to snapshots.                                                                        | Yes                                                                  |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Managed Identity                      | <p>Resource<br>Group</p>   | Microsoft.Managedldentity/userAssignedldentities/read                           | Grants read access to user-assigned managed identities.                                                    | Yes                                                                  | Subscription, Provisioning.Add Instance,Clone,Restore                                          | <p>Public CP DP<br>Private CP DP</p> |
| Managed Identity                      | <p>Resource<br>Group</p>   | Microsoft.Managedldentity/userAssignedldentities/assign/action                  | <p>Allows assigning a user-assigned managed identity to a<br>resource.</p>                                 | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Machines                      | <p>Compute<br>Resource</p> | Microsoft.Compute/virtualMachines/read                                          | Grants read access to virtual machines (VMs).                                                              | <p>Yes<br></p>                                                       | <p>Provisioning,Add Instance,Clone,Restore,Stop<br>Service,Start Service</p>                   | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Machines                      | <p>Compute<br>Resource</p> | Microsoft.Compute/virtualMachines/write                                         | Allows creating or updating virtual machines.                                                              | <p>Yes<br></p>                                                       | <p>Provisioning,Add Instance,Clone,Restore,Stop<br>Service,Start Service</p>                   | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Machines                      | <p>Compute<br>Resource</p> | Microsoft.Compute/virtualMachines/delete                                        | Grants permission to delete virtual machines.                                                              | <p>Yes<br></p>                                                       | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Machines                      | <p>Compute<br>Resource</p> | Microsoft.Compute/virtualMachines/start/action                                  | Allows starting a virtual machine.                                                                         | <p>Yes<br></p>                                                       | Start Service                                                                                  | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Machines                      | <p>Compute<br>Resource</p> | Microsoft.Compute/virtualMachines/powerOff/action                               | Allows powering off a virtual machine.                                                                     | <p>Yes<br></p>                                                       | Stop Service                                                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Machines                      | <p>Compute<br>Resource</p> | Microsoft.Compute/virtualMachines/restart/action                                | Allows restarting a virtual machine.                                                                       | <p>Yes<br></p>                                                       |                                                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Machines                      | <p>Compute<br>Resource</p> | Microsoft.Compute/virtualMachines/runCommand/action                             | Allows running commands on a virtual machine remotely.                                                     | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Machines                      | <p>Compute<br>Resource</p> | Microsoft.Compute/virtualMachines/deallocate/action                             | Allows deallocating a virtual machine.                                                                     | <p>Yes<br></p>                                                       | Delete Service, Delete Instance                                                                | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Network Peerings              | VPC                        | Microsoft.Network/virtualNetworks/virtualNetworkPeerings/read                   | Grants read access to virtual network peerings.                                                            | <p>No<br></p>                                                        | Add Instance                                                                                   | <p>Public CPDP<br>Private CP DP</p>  |
| Virtual Network Peerings              | VPC                        | Microsoft.Network/virtualNetworks/virtualNetworkPeerings/write                  | Allows creating or updating virtual network peerings.                                                      | <p>No<br></p>                                                        | Add Instance                                                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Network Peerings              | VPC                        | Microsoft.Network/virtualNetworks/virtualNetworkPeerings/delete                 | Grants permission to delete virtual network peerings.                                                      | <p>No<br></p>                                                        | Add Instance                                                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Networks                      | VPC                        | Microsoft.Network/virtualNetworks/read                                          | Grants read access to virtual networks.                                                                    | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Networks                      | VPC                        | Microsoft.Network/virtualNetworks/write                                         | Allows creating or updating virtual networks.                                                              | No                                                                   | Add Network                                                                                    | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Networks                      | VPC                        | Microsoft.Network/virtualNetworks/delete                                        | Grants permission to delete virtual networks.                                                              | <p>No<br></p>                                                        | Remove Network                                                                                 | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Networks                      | VPC                        | Microsoft.Network/virtualNetworks/peer/action                                   | Allows peering of virtual networks.                                                                        | <p>No<br></p>                                                        | Add Instance                                                                                   | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Networks                      | VPC                        | Microsoft.Network/virtualNetworks/subnets/read                                  | Grants read access to subnets within a virtual network.                                                    | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Networks                      | VPC                        | Microsoft.Network/virtualNetworks/subnets/join/action                           | Allows subnets to be associated with other resources.                                                      | <p>Yes<br></p>                                                       | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Networks                      | VPC                        | Microsoft.Network/virtualNetworks/subnets/write                                 | Allows creating or updating subnets within a virtual network.                                              | <p>No<br></p>                                                        | Add Network                                                                                    | <p>Public CP DP<br>Private CP DP</p> |
| Virtual Networks                      | VPC                        | Microsoft.Network/virtualNetworks/subnets/delete                                | Grants permission to delete subnets within a virtual network.                                              | No                                                                   | Remove Network                                                                                 | <p>Public CP DP<br>Private CP DP</p> |
| VM Evtensi                            |                            | Microsoft.Compute/virtualMachines/extensions/write                              | Allows adding or updating extensions on virtual machines.                                                  | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
| VM Extensions                         |                            | Microsoft.Compute/virtualMachines/extensions/read                               | Grants read access to virtual machine extensions.                                                          | Yes                                                                  | Provisioning,Add Instance,Clone,Restore                                                        | <p>Public CP DP<br>Private CP DP</p> |
