azure-rbac-custom-role-definition

Custom role names, descriptions, scopes, and permission documents can contain tenant topology or embedded sensitive strings.

azurehigh service: azure:rbac emits ContainsSecret

Where it sits

locationMicrosoft.Authorization/roleDefinitions.properties.{roleName,description,permissions,assignableScopes}
location kindpolicy_document
data kindssensitive_data
emits edgeContainsSecret
serviceAzure RBAC (Authorization) (azure:rbac)

Collection recipe

access moderead_api
operationRole Definitions - Get By Id
response pathproperties
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.Authorization/roleDefinitions/read

References

move · open · esc close