Check access
Find out whether a principal holds an action at a scope, and which role or deny decides it.
Requires: rbac/members/read
The Check access tab answers one question about someone else: does this principal hold this action at this scope, and which role or deny decides it?
Check a principal
- In the portal at https://portal.example.com, open Access control (IAM) and go to Check access.
- Principal — search for the user or group and pick it.
- Action — type the action, for example
containerinstance/read. A role's actions are on its Permissions tab; all actions are listed on the Permissions step of creating a custom role. - Scope — optional; empty means the boundary. Type a resource group or resource scope to check lower down.
- Choose Check access.
Reading the result
| Result | Meaning |
|---|---|
| Access granted | A role assigned to the principal at the scope or above grants the action — the role is named |
| Access denied | A deny assignment blocks the action — the deny is named |
| Not granted | None of the principal's own assignments on this page grants it |
Important
The portal works this answer out from the assignments listed on the Role assignments and Deny assignments tabs. It does not include roles the principal holds through a group, active just-in-time grants, exclusions on deny assignments, or whether a deny applies to child scopes; it treats every action the same whether it is a data action or not, and it matches wildcards more loosely than the platform does. It does not apply the rule that
X/writealso grantsX/delete, so a delete the principal can do may show as Not granted, and a deny ofX/writedoes not show as blockingX/delete. It compares scopes as plain text, so an assignment on resource groupwebalso appears to coverweb2. Read Not granted as "no direct assignment grants it", and check a surprising answer against the assignments of the principal's groups and against its just-in-time requests.
Your own access
The portal also asks the platform, for you, which actions you hold where it shows a page. That is why buttons you cannot use are hidden or disabled rather than failing when you choose them. When something you expect is missing, look up which of the built-in roles carries the action — and where the portal offers it, you can request that role for a few hours.