Azure Defender for Cloud自定义角色配置仅读取权限遇验证错误
解决Azure Defender for Cloud只读自定义角色配置错误
错误原因
你在notActions中使用的权限路径格式不正确,Azure RBAC的Microsoft.Security命名空间下,安全策略、安全解决方案等资源的权限并不包含locations层级,因此Microsoft.Security/locations/securityPolicies/write这类权限名称是无效的,导致验证失败。
正确配置方案
方案1:精准指定只读权限(推荐)
直接在actions中包含所有Azure Defender相关的读取权限,避免使用*带来的不必要权限:
{ "Name": "Azure Defender Reader", "IsCustom": true, "Description": "只读访问Azure Defender for Cloud的所有数据,无法进行任何修改操作", "Actions": [ "Microsoft.Security/alerts/read", "Microsoft.Security/securityPolicies/read", "Microsoft.Security/securitySolutions/read", "Microsoft.Security/securityRecommendations/read", "Microsoft.Security/locations/alerts/read", "Microsoft.Security/locations/securityRecommendations/read", "Microsoft.Security/assessments/read", "Microsoft.Security/scans/read", "Microsoft.Security/secureScores/read" ], "NotActions": [], "AssignableScopes": [ "/subscriptions/你的订阅ID" ] }
方案2:通过NotActions排除修改权限(适配原有配置)
如果坚持使用actions: ["*"],需要修正notActions中的权限名称,移除无效的locations层级,并补充完整的修改类权限:
{ "Name": "Azure Defender Reader", "IsCustom": true, "Description": "只读访问Azure Defender for Cloud,无法修改任何配置或数据", "Actions": [ "*" ], "NotActions": [ "Microsoft.Security/securityPolicies/write", "Microsoft.Security/securityPolicies/delete", "Microsoft.Security/securitySolutions/write", "Microsoft.Security/securitySolutions/delete", "Microsoft.Security/alerts/write", "Microsoft.Security/alerts/delete", "Microsoft.Security/securityRecommendations/write", "Microsoft.Security/securityRecommendations/delete", "Microsoft.Security/assessments/write", "Microsoft.Security/assessments/delete", "Microsoft.Security/secureScores/write" ], "AssignableScopes": [ "/subscriptions/你的订阅ID" ] }
验证方法
- 将配置好的角色分配给测试用户
- 登录Azure门户,尝试修改Defender安全策略、关闭警报、修改推荐状态等操作
- 确认所有修改操作均被拒绝,仅能查看相关数据
内容的提问来源于stack exchange,提问作者Ganapathy
相关产品推荐
相关产品推荐

