您可以通过在notActions中设置特定的资源提供者操作来创建自定义角色,并在资源组级别分配它们。
例如,如果您不希望开发人员删除存储和 Web 应用程序,您可以像这样设置自定义角色:
克隆贡献者。
放入notActions。Microsoft.Web/sites/Delete
_ Microsoft.Storage/storageAccounts/delete
_
"notActions": [
"Microsoft.Authorization/*/Delete",
"Microsoft.Authorization/*/Write",
"Microsoft.Authorization/elevateAccess/Action",
"Microsoft.Blueprint/blueprintAssignments/write",
"Microsoft.Blueprint/blueprintAssignments/delete",
"Microsoft.Compute/galleries/share/action",
"Microsoft.Web/sites/Delete",
"Microsoft.Storage/storageAccounts/delete"
],
创建自定义角色后,将其分配给资源组级别的开发人员。