Mods
Azure

IAM Role: Azure/SQL/admin

PermissionGrant
microsoft.sql/locations/deletevirtualnetworkorsubnets/actionadmin
microsoft.sql/locations/deletedservers/recover/actionadmin
microsoft.sql/locations/instancefailovergroups/deleteadmin
microsoft.sql/locations/instancefailovergroups/failover/actionadmin
microsoft.sql/locations/instancefailovergroups/forcefailoverallowdataloss/actionadmin
microsoft.sql/locations/instancefailovergroups/writeadmin
microsoft.sql/locations/longtermretentionservers/longtermretentiondatabases/longtermretentionbackups/deleteadmin
microsoft.sql/locations/manageddatabaserestoreazureasyncoperation/completerestore/actionadmin
microsoft.sql/managedinstances/administrators/deleteadmin
microsoft.sql/managedinstances/administrators/writeadmin
microsoft.sql/managedinstances/databases/deleteadmin
microsoft.sql/managedinstances/databases/providers/microsoft.insights/diagnosticsettings/writeadmin
microsoft.sql/managedinstances/databases/securityalertpolicies/writeadmin
microsoft.sql/managedinstances/databases/transparentdataencryption/writeadmin
microsoft.sql/managedinstances/databases/vulnerabilityassessments/deleteadmin
microsoft.sql/managedinstances/databases/vulnerabilityassessments/rules/baselines/deleteadmin
microsoft.sql/managedinstances/databases/vulnerabilityassessments/rules/baselines/writeadmin
microsoft.sql/managedinstances/databases/vulnerabilityassessments/writeadmin
microsoft.sql/managedinstances/databases/writeadmin
microsoft.sql/managedinstances/deleteadmin
microsoft.sql/managedinstances/encryptionprotector/writeadmin
microsoft.sql/managedinstances/keys/deleteadmin
microsoft.sql/managedinstances/keys/writeadmin
microsoft.sql/managedinstances/providers/microsoft.insights/diagnosticsettings/writeadmin
microsoft.sql/managedinstances/securityalertpolicies/writeadmin
microsoft.sql/managedinstances/tdecertificates/actionadmin
microsoft.sql/managedinstances/vulnerabilityassessments/deleteadmin
microsoft.sql/managedinstances/vulnerabilityassessments/writeadmin
microsoft.sql/managedinstances/writeadmin
microsoft.sql/servers/administrators/deleteadmin
microsoft.sql/servers/administrators/writeadmin
microsoft.sql/servers/advisors/recommendedactions/writeadmin
microsoft.sql/servers/advisors/writeadmin
microsoft.sql/servers/auditingpolicies/writeadmin
microsoft.sql/servers/auditingsettings/writeadmin
microsoft.sql/servers/automatictuning/writeadmin
microsoft.sql/servers/communicationlinks/deleteadmin
microsoft.sql/servers/communicationlinks/writeadmin
microsoft.sql/servers/connectionpolicies/writeadmin
microsoft.sql/servers/databases/advisors/recommendedactions/writeadmin
microsoft.sql/servers/databases/advisors/writeadmin
microsoft.sql/servers/databases/auditingpolicies/writeadmin
microsoft.sql/servers/databases/auditingsettings/writeadmin
microsoft.sql/servers/databases/automatictuning/writeadmin
microsoft.sql/servers/databases/backuplongtermretentionpolicies/writeadmin
microsoft.sql/servers/databases/connectionpolicies/writeadmin
microsoft.sql/servers/databases/datamaskingpolicies/rules/deleteadmin
microsoft.sql/servers/databases/datamaskingpolicies/rules/writeadmin
microsoft.sql/servers/databases/datamaskingpolicies/writeadmin
microsoft.sql/servers/databases/deleteadmin
microsoft.sql/servers/databases/export/actionadmin
microsoft.sql/servers/databases/extendedauditingsettings/writeadmin
microsoft.sql/servers/databases/extensions/writeadmin
microsoft.sql/servers/databases/geobackuppolicies/writeadmin
microsoft.sql/servers/databases/maintenancewindows/writeadmin
microsoft.sql/servers/databases/move/actionadmin
microsoft.sql/servers/databases/operations/cancel/actionadmin
microsoft.sql/servers/databases/pause/actionadmin
microsoft.sql/servers/databases/providers/microsoft.insights/diagnosticsettings/writeadmin
microsoft.sql/servers/databases/querystore/writeadmin
microsoft.sql/servers/databases/replicationlinks/deleteadmin
microsoft.sql/servers/databases/replicationlinks/failover/actionadmin
microsoft.sql/servers/databases/replicationlinks/forcefailoverallowdataloss/actionadmin
microsoft.sql/servers/databases/replicationlinks/unlink/actionadmin
microsoft.sql/servers/databases/replicationlinks/updatereplicationmode/actionadmin
microsoft.sql/servers/databases/restorepoints/actionadmin
microsoft.sql/servers/databases/restorepoints/deleteadmin
microsoft.sql/servers/databases/resume/actionadmin
microsoft.sql/servers/databases/schemas/tables/columns/sensitivitylabels/deleteadmin
microsoft.sql/servers/databases/schemas/tables/columns/sensitivitylabels/writeadmin
microsoft.sql/servers/databases/schemas/tables/recommendedindexes/writeadmin
microsoft.sql/servers/databases/securityalertpolicies/writeadmin
microsoft.sql/servers/databases/syncgroups/cancelsync/actionadmin
microsoft.sql/servers/databases/syncgroups/deleteadmin
microsoft.sql/servers/databases/syncgroups/refreshhubschema/actionadmin
microsoft.sql/servers/databases/syncgroups/syncmembers/deleteadmin
microsoft.sql/servers/databases/syncgroups/syncmembers/refreshschema/actionadmin
microsoft.sql/servers/databases/syncgroups/syncmembers/writeadmin
microsoft.sql/servers/databases/syncgroups/triggersync/actionadmin
microsoft.sql/servers/databases/syncgroups/writeadmin
microsoft.sql/servers/databases/transparentdataencryption/writeadmin
microsoft.sql/servers/databases/upgradedatawarehouse/actionadmin
microsoft.sql/servers/databases/vulnerabilityassessmentscans/actionadmin
microsoft.sql/servers/databases/vulnerabilityassessmentsettings/writeadmin
microsoft.sql/servers/databases/vulnerabilityassessments/deleteadmin
microsoft.sql/servers/databases/vulnerabilityassessments/rules/baselines/deleteadmin
microsoft.sql/servers/databases/vulnerabilityassessments/rules/baselines/writeadmin
microsoft.sql/servers/databases/vulnerabilityassessments/scans/export/actionadmin
microsoft.sql/servers/databases/vulnerabilityassessments/writeadmin
microsoft.sql/servers/databases/writeadmin
microsoft.sql/servers/deleteadmin
microsoft.sql/servers/disasterrecoveryconfiguration/deleteadmin
microsoft.sql/servers/disasterrecoveryconfiguration/failover/actionadmin
microsoft.sql/servers/disasterrecoveryconfiguration/forcefailoverallowdataloss/actionadmin
microsoft.sql/servers/disasterrecoveryconfiguration/writeadmin
microsoft.sql/servers/elasticpoolestimates/writeadmin
microsoft.sql/servers/elasticpools/advisors/recommendedactions/writeadmin
microsoft.sql/servers/elasticpools/advisors/writeadmin
microsoft.sql/servers/elasticpools/deleteadmin
microsoft.sql/servers/elasticpools/operations/cancel/actionadmin
microsoft.sql/servers/elasticpools/providers/microsoft.insights/diagnosticsettings/writeadmin
microsoft.sql/servers/elasticpools/writeadmin
microsoft.sql/servers/encryptionprotector/writeadmin
microsoft.sql/servers/extendedauditingsettings/writeadmin
microsoft.sql/servers/failovergroups/deleteadmin
microsoft.sql/servers/failovergroups/failover/actionadmin
microsoft.sql/servers/failovergroups/forcefailoverallowdataloss/actionadmin
microsoft.sql/servers/failovergroups/writeadmin
microsoft.sql/servers/firewallrules/deleteadmin
microsoft.sql/servers/firewallrules/writeadmin
microsoft.sql/servers/import/actionadmin
microsoft.sql/servers/interfaceendpointprofiles/deleteadmin
microsoft.sql/servers/interfaceendpointprofiles/writeadmin
microsoft.sql/servers/keys/deleteadmin
microsoft.sql/servers/keys/writeadmin
microsoft.sql/servers/securityalertpolicies/writeadmin
microsoft.sql/servers/syncagents/deleteadmin
microsoft.sql/servers/syncagents/generatekey/actionadmin
microsoft.sql/servers/syncagents/writeadmin
microsoft.sql/servers/tdecertificates/actionadmin
microsoft.sql/servers/virtualnetworkrules/deleteadmin
microsoft.sql/servers/virtualnetworkrules/writeadmin
microsoft.sql/servers/vulnerabilityassessments/deleteadmin
microsoft.sql/servers/vulnerabilityassessments/writeadmin
microsoft.sql/servers/writeadmin
microsoft.sql/virtualclusters/writeadmin
microsoft.resources/deployments/cancel/actionoperator
microsoft.resources/deployments/deleteoperator
microsoft.resources/deployments/validate/actionoperator
microsoft.resources/deployments/writeoperator
microsoft.sql/managedinstances/databases/vulnerabilityassessments/scans/export/actionoperator
microsoft.sql/locations/syncagentoperationresults/readreadonly
microsoft.sql/locations/syncdatabaseids/readreadonly
microsoft.sql/locations/syncgroupoperationresults/readreadonly
microsoft.sql/locations/syncmemberoperationresults/readreadonly
microsoft.sql/locations/virtualnetworkrulesazureasyncoperation/readreadonly
microsoft.sql/locations/virtualnetworkrulesoperationresults/readreadonly
microsoft.sql/managedinstances/readreadonly
microsoft.sql/servers/administrators/readreadonly
microsoft.sql/servers/auditingpolicies/readreadonly
microsoft.sql/servers/connectionpolicies/readreadonly
microsoft.sql/servers/databases/topqueries/querytext/actionreadonly
microsoft.sql/servers/firewallrules/readreadonly
microsoft.sql/servers/importexportoperationresults/readreadonly
microsoft.sql/servers/keys/readreadonly
microsoft.sql/servers/operationresults/readreadonly
microsoft.sql/servers/securityalertpolicies/operationresults/readreadonly
microsoft.sql/servers/securityalertpolicies/readreadonly
microsoft.sql/virtualclusters/readreadonly
microsoft.resources/deployments/operations/readmetadata
microsoft.resources/deployments/readmetadata
microsoft.resources/subscriptions/readmetadata
microsoft.resources/subscriptions/resourcegroups/readmetadata
microsoft.resources/subscriptions/resources/readmetadata
microsoft.sql/locations/auditingsettingsazureasyncoperation/readmetadata
microsoft.sql/locations/auditingsettingsoperationresults/readmetadata
microsoft.sql/locations/capabilities/readmetadata
microsoft.sql/locations/databaseazureasyncoperation/readmetadata
microsoft.sql/locations/databaseoperationresults/readmetadata
microsoft.sql/locations/deletedserverasyncoperation/readmetadata
microsoft.sql/locations/deletedserveroperationresults/readmetadata
microsoft.sql/locations/deletedservers/readmetadata
microsoft.sql/locations/elasticpoolazureasyncoperation/readmetadata
microsoft.sql/locations/elasticpooloperationresults/readmetadata
microsoft.sql/locations/extendedauditingsettingsazureasyncoperation/readmetadata
microsoft.sql/locations/extendedauditingsettingsoperationresults/readmetadata
microsoft.sql/locations/instancefailovergroups/readmetadata
microsoft.sql/locations/interfaceendpointprofileazureasyncoperation/readmetadata
microsoft.sql/locations/interfaceendpointprofileoperationresults/readmetadata
microsoft.sql/locations/longtermretentionbackups/readmetadata
microsoft.sql/locations/longtermretentionservers/longtermretentionbackups/readmetadata
microsoft.sql/locations/longtermretentionservers/longtermretentiondatabases/longtermretentionbackups/readmetadata
microsoft.sql/locations/managedtransparentdataencryptionazureasyncoperation/readmetadata
microsoft.sql/locations/managedtransparentdataencryptionoperationresults/readmetadata
microsoft.sql/locations/readmetadata
microsoft.sql/locations/usages/readmetadata
microsoft.sql/managedinstances/administrators/readmetadata
microsoft.sql/managedinstances/databases/providers/microsoft.insights/diagnosticsettings/readmetadata
microsoft.sql/managedinstances/databases/providers/microsoft.insights/logdefinitions/readmetadata
microsoft.sql/managedinstances/databases/readmetadata
microsoft.sql/managedinstances/databases/securityalertpolicies/readmetadata
microsoft.sql/managedinstances/databases/securityevents/readmetadata
microsoft.sql/managedinstances/databases/transparentdataencryption/readmetadata
microsoft.sql/managedinstances/databases/vulnerabilityassessments/readmetadata
microsoft.sql/managedinstances/databases/vulnerabilityassessments/rules/baselines/readmetadata
microsoft.sql/managedinstances/databases/vulnerabilityassessments/scans/initiatescan/actionmetadata
microsoft.sql/managedinstances/databases/vulnerabilityassessments/scans/readmetadata
microsoft.sql/managedinstances/encryptionprotector/readmetadata
microsoft.sql/managedinstances/keys/readmetadata
microsoft.sql/managedinstances/metricdefinitions/readmetadata
microsoft.sql/managedinstances/metrics/readmetadata
microsoft.sql/managedinstances/providers/microsoft.insights/diagnosticsettings/readmetadata
microsoft.sql/managedinstances/providers/microsoft.insights/logdefinitions/readmetadata
microsoft.sql/managedinstances/providers/microsoft.insights/metricdefinitions/readmetadata
microsoft.sql/managedinstances/securityalertpolicies/readmetadata
microsoft.sql/managedinstances/vulnerabilityassessments/readmetadata
microsoft.sql/operations/readmetadata
microsoft.sql/servers/advisors/readmetadata
microsoft.sql/servers/advisors/recommendedactions/readmetadata
microsoft.sql/servers/auditingsettings/operationresults/readmetadata
microsoft.sql/servers/auditingsettings/readmetadata
microsoft.sql/servers/automatictuning/readmetadata
microsoft.sql/servers/communicationlinks/readmetadata
microsoft.sql/servers/databases/advisors/readmetadata
microsoft.sql/servers/databases/advisors/recommendedactions/readmetadata
microsoft.sql/servers/databases/auditrecords/readmetadata
microsoft.sql/servers/databases/auditingpolicies/readmetadata
microsoft.sql/servers/databases/auditingsettings/readmetadata
microsoft.sql/servers/databases/automatictuning/readmetadata
microsoft.sql/servers/databases/azureasyncoperation/readmetadata
microsoft.sql/servers/databases/backuplongtermretentionpolicies/readmetadata
microsoft.sql/servers/databases/connectionpolicies/readmetadata
microsoft.sql/servers/databases/datamaskingpolicies/readmetadata
microsoft.sql/servers/databases/datamaskingpolicies/rules/readmetadata
microsoft.sql/servers/databases/datawarehousequeries/datawarehousequerysteps/readmetadata
microsoft.sql/servers/databases/datawarehousequeries/readmetadata
microsoft.sql/servers/databases/datawarehouseuseractivities/readmetadata
microsoft.sql/servers/databases/extendedauditingsettings/readmetadata
microsoft.sql/servers/databases/extensions/readmetadata
microsoft.sql/servers/databases/geobackuppolicies/readmetadata
microsoft.sql/servers/databases/importexportoperationresults/readmetadata
microsoft.sql/servers/databases/maintenancewindowoptions/readmetadata
microsoft.sql/servers/databases/maintenancewindows/readmetadata
microsoft.sql/servers/databases/metricdefinitions/readmetadata
microsoft.sql/servers/databases/metrics/readmetadata
microsoft.sql/servers/databases/operationresults/readmetadata
microsoft.sql/servers/databases/operations/readmetadata
microsoft.sql/servers/databases/providers/microsoft.insights/diagnosticsettings/readmetadata
microsoft.sql/servers/databases/providers/microsoft.insights/logdefinitions/readmetadata
microsoft.sql/servers/databases/providers/microsoft.insights/metricdefinitions/readmetadata
microsoft.sql/servers/databases/querystore/querytexts/readmetadata
microsoft.sql/servers/databases/querystore/readmetadata
microsoft.sql/servers/databases/readmetadata
microsoft.sql/servers/databases/replicationlinks/readmetadata
microsoft.sql/servers/databases/restorepoints/readmetadata
microsoft.sql/servers/databases/schemas/readmetadata
microsoft.sql/servers/databases/schemas/tables/columns/readmetadata
microsoft.sql/servers/databases/schemas/tables/columns/sensitivitylabels/readmetadata
microsoft.sql/servers/databases/schemas/tables/readmetadata
microsoft.sql/servers/databases/schemas/tables/recommendedindexes/readmetadata
microsoft.sql/servers/databases/securityalertpolicies/readmetadata
microsoft.sql/servers/databases/securitymetrics/readmetadata
microsoft.sql/servers/databases/sensitivitylabels/readmetadata
microsoft.sql/servers/databases/servicetieradvisors/readmetadata
microsoft.sql/servers/databases/skus/readmetadata
microsoft.sql/servers/databases/syncgroups/hubschemas/readmetadata
microsoft.sql/servers/databases/syncgroups/logs/readmetadata
microsoft.sql/servers/databases/syncgroups/readmetadata
microsoft.sql/servers/databases/syncgroups/refreshhubschemaoperationresults/readmetadata
microsoft.sql/servers/databases/syncgroups/syncmembers/readmetadata
microsoft.sql/servers/databases/syncgroups/syncmembers/refreshschemaoperationresults/readmetadata
microsoft.sql/servers/databases/syncgroups/syncmembers/schemas/readmetadata
microsoft.sql/servers/databases/topqueries/readmetadata
microsoft.sql/servers/databases/topqueries/statistics/readmetadata
microsoft.sql/servers/databases/transparentdataencryption/operationresults/readmetadata
microsoft.sql/servers/databases/transparentdataencryption/readmetadata
microsoft.sql/servers/databases/usages/readmetadata
microsoft.sql/servers/databases/vulnerabilityassessmentscans/operationresults/readmetadata
microsoft.sql/servers/databases/vulnerabilityassessmentsettings/readmetadata
microsoft.sql/servers/databases/vulnerabilityassessments/readmetadata
microsoft.sql/servers/databases/vulnerabilityassessments/rules/baselines/readmetadata
microsoft.sql/servers/databases/vulnerabilityassessments/scans/initiatescan/actionmetadata
microsoft.sql/servers/databases/vulnerabilityassessments/scans/readmetadata
microsoft.sql/servers/disasterrecoveryconfiguration/readmetadata
microsoft.sql/servers/elasticpoolestimates/readmetadata
microsoft.sql/servers/elasticpools/advisors/readmetadata
microsoft.sql/servers/elasticpools/advisors/recommendedactions/readmetadata
microsoft.sql/servers/elasticpools/databases/readmetadata
microsoft.sql/servers/elasticpools/elasticpoolactivity/readmetadata
microsoft.sql/servers/elasticpools/elasticpooldatabaseactivity/readmetadata
microsoft.sql/servers/elasticpools/metricdefinitions/readmetadata
microsoft.sql/servers/elasticpools/metrics/readmetadata
microsoft.sql/servers/elasticpools/operations/readmetadata
microsoft.sql/servers/elasticpools/providers/microsoft.insights/diagnosticsettings/readmetadata
microsoft.sql/servers/elasticpools/providers/microsoft.insights/metricdefinitions/readmetadata
microsoft.sql/servers/elasticpools/readmetadata
microsoft.sql/servers/elasticpools/skus/readmetadata
microsoft.sql/servers/encryptionprotector/readmetadata
microsoft.sql/servers/extendedauditingsettings/readmetadata
microsoft.sql/servers/failovergroups/readmetadata
microsoft.sql/servers/interfaceendpointprofiles/readmetadata
microsoft.sql/servers/providers/microsoft.insights/metricdefinitions/readmetadata
microsoft.sql/servers/readmetadata
microsoft.sql/servers/recommendedelasticpools/databases/readmetadata
microsoft.sql/servers/recommendedelasticpools/readmetadata
microsoft.sql/servers/recoverabledatabases/readmetadata
microsoft.sql/servers/replicationlinks/readmetadata
microsoft.sql/servers/restorabledroppeddatabases/readmetadata
microsoft.sql/servers/serviceobjectives/readmetadata
microsoft.sql/servers/syncagents/linkeddatabases/readmetadata
microsoft.sql/servers/syncagents/readmetadata
microsoft.sql/servers/usages/readmetadata
microsoft.sql/servers/virtualnetworkrules/readmetadata
microsoft.sql/servers/vulnerabilityassessments/readmetadata
microsoft.storage/storageaccounts/readmetadata