Azure role permits custom role creation

Limit creation and modification of Azure custom roles to the administrators who need it.

Description

Microsoft.Authorization/roleDefinitions/write permits creating or modifying custom roles within authorized scopes. Permission to define a role is distinct from permission to assign it to a principal.

Potential impact

Expanding an already assigned role, or combining a new role with separate role-assignment permissions, can increase access beyond what was intended.

Remediation

Remove this action from principals that do not manage roles and allow only the operations they need. Restrict role changes to authorized administrators and check their effects on existing assignments.

Examples

The examples narrow role-definition management to VM read access. Replace the subscription ID and verify the management permissions required for the intended scopes.

Before

yaml
- name: 역할 정의 생성
  azure_rm_roledefinition:
    name: myTestRole
    scope: /subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/resourceGroups/myresourceGroup
    permissions:
      - actions:
          - Microsoft.Authorization/roleDefinitions/write
    assignable_scopes:
      - /subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx

After

yaml
- name: 역할 정의 생성
  azure_rm_roledefinition:
    name: myTestRole
    scope: /subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/resourceGroups/myresourceGroup
    permissions:
      - actions:
          - Microsoft.Compute/virtualMachines/read
    assignable_scopes:
      - /subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx

References