Description
Microsoft.Authorization/roleDefinitions/write permits creating or changing custom roles. It is separate from role-assignment permission, but changing an already assigned role can affect users’ effective permissions.
Potential impact
An erroneous or malicious role-definition change can expand access for accounts using that role.
Remediation
Remove this action and broad wildcards that include it from accounts that do not manage roles. Allow only role-definition read access when inspection is sufficient.
Examples
These excerpts reduce role-definition write permission to read permission.
Before
hcl
resource "azurerm_role_definition" "example" {
role_definition_id = "00000000-0000-0000-0000-000000000000"
name = "my-custom-role-definition"
scope = data.azurerm_subscription.primary.id
permissions {
actions = ["Microsoft.Authorization/roleDefinitions/write"]
not_actions = []
}
}
After
hcl
resource "azurerm_role_definition" "example" {
role_definition_id = "00000000-0000-0000-0000-000000000000"
name = "my-custom-role-definition"
scope = data.azurerm_subscription.primary.id
permissions {
actions = ["Microsoft.Authorization/roleDefinitions/read"]
not_actions = []
}
}