azure-rbac-role-assignment-condition
Role-assignment conditions and descriptions may reveal principal identifiers, resource selectors, and operator-entered text.
Where it sits
| location | Microsoft.Authorization/roleAssignments.properties.{principalId,condition,conditionVersion,description} |
| location kind | policy_document |
| data kinds | sensitive_data |
| emits edge | ContainsSecret |
| service | Azure RBAC (Authorization) (azure:rbac) |
Collection recipe
| access mode | read_api |
| operation | Role Assignments - Get |
| response path | properties.{principalId,condition,conditionVersion,description} |
| encoding | json |
| params | {"resource_id": "\u003cazure-resource-id\u003e"} |
Required permissions
Microsoft.Authorization/roleAssignments/read
References