This is the latest version of Azure Native. Use the Azure Native v2 docs if using the v2 version of this package.
Viewing docs for Azure Native v3.25.0
published on Wednesday, Aug 5, 2026 by Pulumi
published on Wednesday, Aug 5, 2026 by Pulumi
This is the latest version of Azure Native. Use the Azure Native v2 docs if using the v2 version of this package.
Viewing docs for Azure Native v3.25.0
published on Wednesday, Aug 5, 2026 by Pulumi
published on Wednesday, Aug 5, 2026 by Pulumi
Get a role assignment by scope and name.
Uses Azure REST API version 2022-04-01.
Other available API versions: 2020-08-01-preview, 2020-10-01-preview. These can be accessed by generating a local SDK package using the CLI command pulumi package add azure-native authorization [ApiVersion]. See the version guide for details.
Using getRoleAssignment
Two invocation forms are available. The direct form accepts plain arguments and either blocks until the result value is available, or returns a Promise-wrapped result. The output form accepts Input-wrapped arguments and returns an Output-wrapped result.
function getRoleAssignment(args: GetRoleAssignmentArgs, opts?: InvokeOptions): Promise<GetRoleAssignmentResult>
function getRoleAssignmentOutput(args: GetRoleAssignmentOutputArgs, opts?: InvokeOptions): Output<GetRoleAssignmentResult>def get_role_assignment(role_assignment_name: Optional[str] = None,
scope: Optional[str] = None,
tenant_id: Optional[str] = None,
opts: Optional[InvokeOptions] = None) -> GetRoleAssignmentResult
def get_role_assignment_output(role_assignment_name: pulumi.Input[Optional[str]] = None,
scope: pulumi.Input[Optional[str]] = None,
tenant_id: pulumi.Input[Optional[str]] = None,
opts: Optional[InvokeOptions] = None) -> Output[GetRoleAssignmentResult]func LookupRoleAssignment(ctx *Context, args *LookupRoleAssignmentArgs, opts ...InvokeOption) (*LookupRoleAssignmentResult, error)
func LookupRoleAssignmentOutput(ctx *Context, args *LookupRoleAssignmentOutputArgs, opts ...InvokeOption) LookupRoleAssignmentResultOutput> Note: This function is named LookupRoleAssignment in the Go SDK.
public static class GetRoleAssignment
{
public static Task<GetRoleAssignmentResult> InvokeAsync(GetRoleAssignmentArgs args, InvokeOptions? opts = null)
public static Output<GetRoleAssignmentResult> Invoke(GetRoleAssignmentInvokeArgs args, InvokeOptions? opts = null)
}public static CompletableFuture<GetRoleAssignmentResult> getRoleAssignment(GetRoleAssignmentArgs args, InvokeOptions options)
public static Output<GetRoleAssignmentResult> getRoleAssignment(GetRoleAssignmentArgs args, InvokeOptions options)
fn::invoke:
function: azure-native:authorization:getRoleAssignment
arguments:
# arguments dictionarydata "azure-native_authorization_get_role_assignment" "name" {
# arguments
}The following arguments are supported:
- Role
Assignment stringName - The name of the role assignment. It can be any valid GUID.
- Scope string
- The fully qualified Azure Resource manager identifier of the resource.
- Tenant
Id string - Tenant ID for cross-tenant request
- Role
Assignment stringName - The name of the role assignment. It can be any valid GUID.
- Scope string
- The fully qualified Azure Resource manager identifier of the resource.
- Tenant
Id string - Tenant ID for cross-tenant request
- role_
assignment_ stringname - The name of the role assignment. It can be any valid GUID.
- scope string
- The fully qualified Azure Resource manager identifier of the resource.
- tenant_
id string - Tenant ID for cross-tenant request
- role
Assignment StringName - The name of the role assignment. It can be any valid GUID.
- scope String
- The fully qualified Azure Resource manager identifier of the resource.
- tenant
Id String - Tenant ID for cross-tenant request
- role
Assignment stringName - The name of the role assignment. It can be any valid GUID.
- scope string
- The fully qualified Azure Resource manager identifier of the resource.
- tenant
Id string - Tenant ID for cross-tenant request
- role_
assignment_ strname - The name of the role assignment. It can be any valid GUID.
- scope str
- The fully qualified Azure Resource manager identifier of the resource.
- tenant_
id str - Tenant ID for cross-tenant request
- role
Assignment StringName - The name of the role assignment. It can be any valid GUID.
- scope String
- The fully qualified Azure Resource manager identifier of the resource.
- tenant
Id String - Tenant ID for cross-tenant request
getRoleAssignment Result
The following output properties are available:
- Azure
Api stringVersion - The Azure API version of the resource.
- Created
By string - Id of the user who created the assignment
- Created
On string - Time it was created
- Id string
- Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}
- Name string
- The name of the resource
- Principal
Id string - The principal ID.
- Role
Definition stringId - The role definition ID.
- Scope string
- The role assignment scope.
- System
Data Pulumi.Azure Native. Authorization. Outputs. System Data Response - Azure Resource Manager metadata containing createdBy and modifiedBy information.
- Type string
- The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts"
- Updated
By string - Id of the user who updated the assignment
- Updated
On string - Time it was updated
- Condition string
- The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'
- Condition
Version string - Version of the condition. Currently the only accepted value is '2.0'
- Delegated
Managed stringIdentity Resource Id - Id of the delegated managed identity resource
- Description string
- Description of role assignment
- Principal
Type string - The principal type of the assigned principal ID.
- Azure
Api stringVersion - The Azure API version of the resource.
- Created
By string - Id of the user who created the assignment
- Created
On string - Time it was created
- Id string
- Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}
- Name string
- The name of the resource
- Principal
Id string - The principal ID.
- Role
Definition stringId - The role definition ID.
- Scope string
- The role assignment scope.
- System
Data SystemData Response - Azure Resource Manager metadata containing createdBy and modifiedBy information.
- Type string
- The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts"
- Updated
By string - Id of the user who updated the assignment
- Updated
On string - Time it was updated
- Condition string
- The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'
- Condition
Version string - Version of the condition. Currently the only accepted value is '2.0'
- Delegated
Managed stringIdentity Resource Id - Id of the delegated managed identity resource
- Description string
- Description of role assignment
- Principal
Type string - The principal type of the assigned principal ID.
- azure_
api_ stringversion - The Azure API version of the resource.
- created_
by string - Id of the user who created the assignment
- created_
on string - Time it was created
- id string
- Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}
- name string
- The name of the resource
- principal_
id string - The principal ID.
- role_
definition_ stringid - The role definition ID.
- scope string
- The role assignment scope.
- system_
data object - Azure Resource Manager metadata containing createdBy and modifiedBy information.
- type string
- The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts"
- updated_
by string - Id of the user who updated the assignment
- updated_
on string - Time it was updated
- condition string
- The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'
- condition_
version string - Version of the condition. Currently the only accepted value is '2.0'
- delegated_
managed_ stringidentity_ resource_ id - Id of the delegated managed identity resource
- description string
- Description of role assignment
- principal_
type string - The principal type of the assigned principal ID.
- azure
Api StringVersion - The Azure API version of the resource.
- created
By String - Id of the user who created the assignment
- created
On String - Time it was created
- id String
- Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}
- name String
- The name of the resource
- principal
Id String - The principal ID.
- role
Definition StringId - The role definition ID.
- scope String
- The role assignment scope.
- system
Data SystemData Response - Azure Resource Manager metadata containing createdBy and modifiedBy information.
- type String
- The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts"
- updated
By String - Id of the user who updated the assignment
- updated
On String - Time it was updated
- condition String
- The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'
- condition
Version String - Version of the condition. Currently the only accepted value is '2.0'
- delegated
Managed StringIdentity Resource Id - Id of the delegated managed identity resource
- description String
- Description of role assignment
- principal
Type String - The principal type of the assigned principal ID.
- azure
Api stringVersion - The Azure API version of the resource.
- created
By string - Id of the user who created the assignment
- created
On string - Time it was created
- id string
- Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}
- name string
- The name of the resource
- principal
Id string - The principal ID.
- role
Definition stringId - The role definition ID.
- scope string
- The role assignment scope.
- system
Data SystemData Response - Azure Resource Manager metadata containing createdBy and modifiedBy information.
- type string
- The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts"
- updated
By string - Id of the user who updated the assignment
- updated
On string - Time it was updated
- condition string
- The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'
- condition
Version string - Version of the condition. Currently the only accepted value is '2.0'
- delegated
Managed stringIdentity Resource Id - Id of the delegated managed identity resource
- description string
- Description of role assignment
- principal
Type string - The principal type of the assigned principal ID.
- azure_
api_ strversion - The Azure API version of the resource.
- created_
by str - Id of the user who created the assignment
- created_
on str - Time it was created
- id str
- Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}
- name str
- The name of the resource
- principal_
id str - The principal ID.
- role_
definition_ strid - The role definition ID.
- scope str
- The role assignment scope.
- system_
data SystemData Response - Azure Resource Manager metadata containing createdBy and modifiedBy information.
- type str
- The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts"
- updated_
by str - Id of the user who updated the assignment
- updated_
on str - Time it was updated
- condition str
- The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'
- condition_
version str - Version of the condition. Currently the only accepted value is '2.0'
- delegated_
managed_ stridentity_ resource_ id - Id of the delegated managed identity resource
- description str
- Description of role assignment
- principal_
type str - The principal type of the assigned principal ID.
- azure
Api StringVersion - The Azure API version of the resource.
- created
By String - Id of the user who created the assignment
- created
On String - Time it was created
- id String
- Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}
- name String
- The name of the resource
- principal
Id String - The principal ID.
- role
Definition StringId - The role definition ID.
- scope String
- The role assignment scope.
- system
Data Property Map - Azure Resource Manager metadata containing createdBy and modifiedBy information.
- type String
- The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts"
- updated
By String - Id of the user who updated the assignment
- updated
On String - Time it was updated
- condition String
- The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'
- condition
Version String - Version of the condition. Currently the only accepted value is '2.0'
- delegated
Managed StringIdentity Resource Id - Id of the delegated managed identity resource
- description String
- Description of role assignment
- principal
Type String - The principal type of the assigned principal ID.
Supporting Types
SystemDataResponse
- Created
At string - The timestamp of resource creation (UTC).
- Created
By string - The identity that created the resource.
- Created
By stringType - The type of identity that created the resource.
- Last
Modified stringAt - The timestamp of resource last modification (UTC)
- Last
Modified stringBy - The identity that last modified the resource.
- Last
Modified stringBy Type - The type of identity that last modified the resource.
- Created
At string - The timestamp of resource creation (UTC).
- Created
By string - The identity that created the resource.
- Created
By stringType - The type of identity that created the resource.
- Last
Modified stringAt - The timestamp of resource last modification (UTC)
- Last
Modified stringBy - The identity that last modified the resource.
- Last
Modified stringBy Type - The type of identity that last modified the resource.
- created_
at string - The timestamp of resource creation (UTC).
- created_
by string - The identity that created the resource.
- created_
by_ stringtype - The type of identity that created the resource.
- last_
modified_ stringat - The timestamp of resource last modification (UTC)
- last_
modified_ stringby - The identity that last modified the resource.
- last_
modified_ stringby_ type - The type of identity that last modified the resource.
- created
At String - The timestamp of resource creation (UTC).
- created
By String - The identity that created the resource.
- created
By StringType - The type of identity that created the resource.
- last
Modified StringAt - The timestamp of resource last modification (UTC)
- last
Modified StringBy - The identity that last modified the resource.
- last
Modified StringBy Type - The type of identity that last modified the resource.
- created
At string - The timestamp of resource creation (UTC).
- created
By string - The identity that created the resource.
- created
By stringType - The type of identity that created the resource.
- last
Modified stringAt - The timestamp of resource last modification (UTC)
- last
Modified stringBy - The identity that last modified the resource.
- last
Modified stringBy Type - The type of identity that last modified the resource.
- created_
at str - The timestamp of resource creation (UTC).
- created_
by str - The identity that created the resource.
- created_
by_ strtype - The type of identity that created the resource.
- last_
modified_ strat - The timestamp of resource last modification (UTC)
- last_
modified_ strby - The identity that last modified the resource.
- last_
modified_ strby_ type - The type of identity that last modified the resource.
- created
At String - The timestamp of resource creation (UTC).
- created
By String - The identity that created the resource.
- created
By StringType - The type of identity that created the resource.
- last
Modified StringAt - The timestamp of resource last modification (UTC)
- last
Modified StringBy - The identity that last modified the resource.
- last
Modified StringBy Type - The type of identity that last modified the resource.
Package Details
- Repository
- Azure Native pulumi/pulumi-azure-native
- License
- Apache-2.0
This is the latest version of Azure Native. Use the Azure Native v2 docs if using the v2 version of this package.
Viewing docs for Azure Native v3.25.0
published on Wednesday, Aug 5, 2026 by Pulumi
published on Wednesday, Aug 5, 2026 by Pulumi