Mods
Azure

IAM Role: Azure/AKS/admin

PermissionGrant
microsoft.containerservice/containerservices/writeadmin
microsoft.containerservice/containerservices/deleteadmin
microsoft.containerservice/managedclusters/writeadmin
microsoft.containerservice/managedclusters/deleteadmin
microsoft.containerservice/managedclusters/listclusteradmincredential/actionadmin
microsoft.containerservice/managedclusters/listclusterusercredential/actionadmin
microsoft.containerservice/managedclusters/resetserviceprincipalprofile/actionadmin
microsoft.containerservice/managedclusters/resetaadprofile/actionadmin
microsoft.containerservice/managedclusters/privateendpointconnectionsapproval/actionadmin
microsoft.containerservice/managedclusters/providers/microsoft.insights/diagnosticsettings/writeadmin
microsoft.containerservice/managedclusters/accessprofiles/listcredential/actionadmin
microsoft.containerservice/openshiftmanagedclusters/writeadmin
microsoft.containerservice/openshiftmanagedclusters/deleteadmin
microsoft.containerservice/openshiftclusters/writeadmin
microsoft.containerservice/openshiftclusters/deleteadmin
microsoft.containerservice/managedclusters/agentpools/writeadmin
microsoft.containerservice/managedclusters/agentpools/deleteadmin
microsoft.containerservice/managedclusters/listclustermonitoringusercredential/actionadmin
microsoft.containerservice/managedclusters/rotateclustercertificates/actionadmin
microsoft.containerservice/register/actionadmin
microsoft.containerservice/unregister/actionadmin
microsoft.resources/deployments/cancel/actionadmin
microsoft.resources/deployments/deleteadmin
microsoft.resources/deployments/validate/actionadmin
microsoft.resources/deployments/writeadmin
microsoft.containerservice/containerservices/readmetadata
microsoft.containerservice/managedclusters/readmetadata
microsoft.containerservice/managedclusters/providers/microsoft.insights/diagnosticsettings/readmetadata
microsoft.containerservice/managedclusters/providers/microsoft.insights/metricdefinitions/readmetadata
microsoft.containerservice/managedclusters/accessprofiles/readmetadata
microsoft.containerservice/managedclusters/providers/microsoft.insights/logdefinitions/readmetadata
microsoft.containerservice/locations/operations/readmetadata
microsoft.containerservice/locations/orchestrators/readmetadata
microsoft.containerservice/managedclusters/upgradeprofiles/readmetadata
microsoft.containerservice/operations/readmetadata
microsoft.containerservice/locations/operationresults/readmetadata
microsoft.containerservice/openshiftmanagedclusters/readmetadata
microsoft.containerservice/openshiftclusters/readmetadata
microsoft.containerservice/managedclusters/agentpools/readmetadata
microsoft.containerservice/managedclusters/detectors/readmetadata
microsoft.containerservice/managedclusters/agentpools/upgradeProfiles/readmetadata
microsoft.containerservice/managedclusters/diagnosticsstate/readmetadata
microsoft.containerservice/managedclusters/availableagentpoolversions/readmetadata
microsoft.resources/deployments/operations/readmetadata
microsoft.resources/deployments/readmetadata
microsoft.resources/subscriptions/resourcegroups/readmetadata