Permissions
The actions that govern managed identities, and the roles that hold them.
Actions
| Action | Allows |
|---|---|
managedidentities/read |
Listing the identities in a resource group and viewing one — the Managed Identity card |
managedidentities/write |
Creating an identity for a resource directly. The platform does this itself when the resource is created |
managedidentities/delete |
Deleting an identity directly. The platform does this itself when the resource is deleted |
managedidentities/readSecrets |
Reading an identity's client ID and client secret — a data action |
managedidentities/readSecrets hands out a credential that does not expire and lets the holder
act as the workload, with every right the identity's roles give. Workloads do not need it: they
get short-lived tokens without it — see Use a managed identity in code.
Roles
| Role | read | write, delete | readSecrets |
|---|---|---|---|
| Reader | Yes | No | No |
| The Apps, Functions, Jobs, Databases and Storage Reader and Operator roles, Blueprint Reader, Blueprints Operator | Yes | No | No |
| Contributor, Owner | Yes | Yes | Yes |
| Platform Reader | Yes | No | No |
| Platform Contributor, Platform Owner | Yes | Yes | Yes |
Owner, Contributor and the two platform roles hold managedidentities/readSecrets through their
data-action wildcard. To keep it from someone who needs Contributor otherwise, exclude it with a
deny assignment.