Description
Microsoft.Authorization/roleDefinitions/write permits creating or modifying custom roles within authorized scopes. Permission to define a role is distinct from permission to assign it to a principal.
Potential impact
Expanding an already assigned role, or combining a new role with separate role-assignment permissions, can increase access beyond what was intended.
Remediation
Remove this action from principals that do not manage roles and allow only the operations they need. Restrict role changes to authorized administrators and check their effects on existing assignments.
Examples
The examples narrow role-definition management to VM read access. Replace the subscription ID and verify the management permissions required for the intended scopes.
Before
- name: 역할 정의 생성
azure_rm_roledefinition:
name: myTestRole
scope: /subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/resourceGroups/myresourceGroup
permissions:
- actions:
- Microsoft.Authorization/roleDefinitions/write
assignable_scopes:
- /subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
After
- name: 역할 정의 생성
azure_rm_roledefinition:
name: myTestRole
scope: /subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/resourceGroups/myresourceGroup
permissions:
- actions:
- Microsoft.Compute/virtualMachines/read
assignable_scopes:
- /subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx