1. Packages
  2. Packages
  3. Azure Native
  4. API Docs
  5. authorization
  6. RoleAssignment
This is the latest version of Azure Native. Use the Azure Native v2 docs if using the v2 version of this package.
Viewing docs for Azure Native v3.26.0
published on Thursday, Aug 13, 2026 by Pulumi
azure-native logo
This is the latest version of Azure Native. Use the Azure Native v2 docs if using the v2 version of this package.
Viewing docs for Azure Native v3.26.0
published on Thursday, Aug 13, 2026 by Pulumi

    Role Assignments

    Uses Azure REST API version 2022-04-01. In version 2.x of the Azure Native provider, it used API version 2022-04-01.

    Other available API versions: 2020-08-01-preview, 2020-10-01-preview. These can be accessed by generating a local SDK package using the CLI command pulumi package add azure-native authorization [ApiVersion]. See the version guide for details.

    Example Usage

    Create role assignment for resource

    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using AzureNative = Pulumi.AzureNative;
    
    return await Deployment.RunAsync(() => 
    {
        var roleAssignment = new AzureNative.Authorization.RoleAssignment("roleAssignment", new()
        {
            PrincipalId = "ce2ce14e-85d7-4629-bdbc-454d0519d987",
            PrincipalType = AzureNative.Authorization.PrincipalType.User,
            RoleAssignmentName = "05c5a614-a7d6-4502-b150-c2fb455033ff",
            RoleDefinitionId = "/subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d",
            Scope = "subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/resourceGroups/testrg/providers/Microsoft.DocumentDb/databaseAccounts/test-db-account",
        });
    
    });
    
    package main
    
    import (
    	authorization "github.com/pulumi/pulumi-azure-native-sdk/authorization/v3"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		_, err := authorization.NewRoleAssignment(ctx, "roleAssignment", &authorization.RoleAssignmentArgs{
    			PrincipalId:        pulumi.String("ce2ce14e-85d7-4629-bdbc-454d0519d987"),
    			PrincipalType:      pulumi.String(authorization.PrincipalTypeUser),
    			RoleAssignmentName: pulumi.String("05c5a614-a7d6-4502-b150-c2fb455033ff"),
    			RoleDefinitionId:   pulumi.String("/subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d"),
    			Scope:              pulumi.String("subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/resourceGroups/testrg/providers/Microsoft.DocumentDb/databaseAccounts/test-db-account"),
    		})
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    pulumi {
      required_providers {
        azure-native = {
          source = "pulumi/azure-native"
        }
      }
    }
    
    resource "azure-native_authorization_roleassignment" "roleAssignment" {
      principal_id         = "ce2ce14e-85d7-4629-bdbc-454d0519d987"
      principal_type       = "User"
      role_assignment_name = "05c5a614-a7d6-4502-b150-c2fb455033ff"
      role_definition_id   = "/subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d"
      scope                = "subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/resourceGroups/testrg/providers/Microsoft.DocumentDb/databaseAccounts/test-db-account"
    }
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.azurenative.authorization.RoleAssignment;
    import com.pulumi.azurenative.authorization.RoleAssignmentArgs;
    import java.util.ArrayList;
    import java.util.Arrays;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            var roleAssignment = new RoleAssignment("roleAssignment", RoleAssignmentArgs.builder()
                .principalId("ce2ce14e-85d7-4629-bdbc-454d0519d987")
                .principalType("User")
                .roleAssignmentName("05c5a614-a7d6-4502-b150-c2fb455033ff")
                .roleDefinitionId("/subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d")
                .scope("subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/resourceGroups/testrg/providers/Microsoft.DocumentDb/databaseAccounts/test-db-account")
                .build());
    
        }
    }
    
    import * as pulumi from "@pulumi/pulumi";
    import * as azure_native from "@pulumi/azure-native";
    
    const roleAssignment = new azure_native.authorization.RoleAssignment("roleAssignment", {
        principalId: "ce2ce14e-85d7-4629-bdbc-454d0519d987",
        principalType: azure_native.authorization.PrincipalType.User,
        roleAssignmentName: "05c5a614-a7d6-4502-b150-c2fb455033ff",
        roleDefinitionId: "/subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d",
        scope: "subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/resourceGroups/testrg/providers/Microsoft.DocumentDb/databaseAccounts/test-db-account",
    });
    
    import pulumi
    import pulumi_azure_native as azure_native
    
    role_assignment = azure_native.authorization.RoleAssignment("roleAssignment",
        principal_id="ce2ce14e-85d7-4629-bdbc-454d0519d987",
        principal_type=azure_native.authorization.PrincipalType.USER,
        role_assignment_name="05c5a614-a7d6-4502-b150-c2fb455033ff",
        role_definition_id="/subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d",
        scope="subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/resourceGroups/testrg/providers/Microsoft.DocumentDb/databaseAccounts/test-db-account")
    
    resources:
      roleAssignment:
        type: azure-native:authorization:RoleAssignment
        properties:
          principalId: ce2ce14e-85d7-4629-bdbc-454d0519d987
          principalType: User
          roleAssignmentName: 05c5a614-a7d6-4502-b150-c2fb455033ff
          roleDefinitionId: /subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d
          scope: subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/resourceGroups/testrg/providers/Microsoft.DocumentDb/databaseAccounts/test-db-account
    

    Create role assignment for resource group

    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using AzureNative = Pulumi.AzureNative;
    
    return await Deployment.RunAsync(() => 
    {
        var roleAssignment = new AzureNative.Authorization.RoleAssignment("roleAssignment", new()
        {
            PrincipalId = "ce2ce14e-85d7-4629-bdbc-454d0519d987",
            PrincipalType = AzureNative.Authorization.PrincipalType.User,
            RoleAssignmentName = "05c5a614-a7d6-4502-b150-c2fb455033ff",
            RoleDefinitionId = "/subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d",
            Scope = "subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/resourceGroups/testrg",
        });
    
    });
    
    package main
    
    import (
    	authorization "github.com/pulumi/pulumi-azure-native-sdk/authorization/v3"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		_, err := authorization.NewRoleAssignment(ctx, "roleAssignment", &authorization.RoleAssignmentArgs{
    			PrincipalId:        pulumi.String("ce2ce14e-85d7-4629-bdbc-454d0519d987"),
    			PrincipalType:      pulumi.String(authorization.PrincipalTypeUser),
    			RoleAssignmentName: pulumi.String("05c5a614-a7d6-4502-b150-c2fb455033ff"),
    			RoleDefinitionId:   pulumi.String("/subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d"),
    			Scope:              pulumi.String("subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/resourceGroups/testrg"),
    		})
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    pulumi {
      required_providers {
        azure-native = {
          source = "pulumi/azure-native"
        }
      }
    }
    
    resource "azure-native_authorization_roleassignment" "roleAssignment" {
      principal_id         = "ce2ce14e-85d7-4629-bdbc-454d0519d987"
      principal_type       = "User"
      role_assignment_name = "05c5a614-a7d6-4502-b150-c2fb455033ff"
      role_definition_id   = "/subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d"
      scope                = "subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/resourceGroups/testrg"
    }
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.azurenative.authorization.RoleAssignment;
    import com.pulumi.azurenative.authorization.RoleAssignmentArgs;
    import java.util.ArrayList;
    import java.util.Arrays;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            var roleAssignment = new RoleAssignment("roleAssignment", RoleAssignmentArgs.builder()
                .principalId("ce2ce14e-85d7-4629-bdbc-454d0519d987")
                .principalType("User")
                .roleAssignmentName("05c5a614-a7d6-4502-b150-c2fb455033ff")
                .roleDefinitionId("/subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d")
                .scope("subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/resourceGroups/testrg")
                .build());
    
        }
    }
    
    import * as pulumi from "@pulumi/pulumi";
    import * as azure_native from "@pulumi/azure-native";
    
    const roleAssignment = new azure_native.authorization.RoleAssignment("roleAssignment", {
        principalId: "ce2ce14e-85d7-4629-bdbc-454d0519d987",
        principalType: azure_native.authorization.PrincipalType.User,
        roleAssignmentName: "05c5a614-a7d6-4502-b150-c2fb455033ff",
        roleDefinitionId: "/subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d",
        scope: "subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/resourceGroups/testrg",
    });
    
    import pulumi
    import pulumi_azure_native as azure_native
    
    role_assignment = azure_native.authorization.RoleAssignment("roleAssignment",
        principal_id="ce2ce14e-85d7-4629-bdbc-454d0519d987",
        principal_type=azure_native.authorization.PrincipalType.USER,
        role_assignment_name="05c5a614-a7d6-4502-b150-c2fb455033ff",
        role_definition_id="/subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d",
        scope="subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/resourceGroups/testrg")
    
    resources:
      roleAssignment:
        type: azure-native:authorization:RoleAssignment
        properties:
          principalId: ce2ce14e-85d7-4629-bdbc-454d0519d987
          principalType: User
          roleAssignmentName: 05c5a614-a7d6-4502-b150-c2fb455033ff
          roleDefinitionId: /subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d
          scope: subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/resourceGroups/testrg
    

    Create role assignment for subscription

    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using AzureNative = Pulumi.AzureNative;
    
    return await Deployment.RunAsync(() => 
    {
        var roleAssignment = new AzureNative.Authorization.RoleAssignment("roleAssignment", new()
        {
            PrincipalId = "ce2ce14e-85d7-4629-bdbc-454d0519d987",
            PrincipalType = AzureNative.Authorization.PrincipalType.User,
            RoleAssignmentName = "05c5a614-a7d6-4502-b150-c2fb455033ff",
            RoleDefinitionId = "/subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d",
            Scope = "subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2",
        });
    
    });
    
    package main
    
    import (
    	authorization "github.com/pulumi/pulumi-azure-native-sdk/authorization/v3"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		_, err := authorization.NewRoleAssignment(ctx, "roleAssignment", &authorization.RoleAssignmentArgs{
    			PrincipalId:        pulumi.String("ce2ce14e-85d7-4629-bdbc-454d0519d987"),
    			PrincipalType:      pulumi.String(authorization.PrincipalTypeUser),
    			RoleAssignmentName: pulumi.String("05c5a614-a7d6-4502-b150-c2fb455033ff"),
    			RoleDefinitionId:   pulumi.String("/subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d"),
    			Scope:              pulumi.String("subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2"),
    		})
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    pulumi {
      required_providers {
        azure-native = {
          source = "pulumi/azure-native"
        }
      }
    }
    
    resource "azure-native_authorization_roleassignment" "roleAssignment" {
      principal_id         = "ce2ce14e-85d7-4629-bdbc-454d0519d987"
      principal_type       = "User"
      role_assignment_name = "05c5a614-a7d6-4502-b150-c2fb455033ff"
      role_definition_id   = "/subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d"
      scope                = "subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2"
    }
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.azurenative.authorization.RoleAssignment;
    import com.pulumi.azurenative.authorization.RoleAssignmentArgs;
    import java.util.ArrayList;
    import java.util.Arrays;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            var roleAssignment = new RoleAssignment("roleAssignment", RoleAssignmentArgs.builder()
                .principalId("ce2ce14e-85d7-4629-bdbc-454d0519d987")
                .principalType("User")
                .roleAssignmentName("05c5a614-a7d6-4502-b150-c2fb455033ff")
                .roleDefinitionId("/subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d")
                .scope("subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2")
                .build());
    
        }
    }
    
    import * as pulumi from "@pulumi/pulumi";
    import * as azure_native from "@pulumi/azure-native";
    
    const roleAssignment = new azure_native.authorization.RoleAssignment("roleAssignment", {
        principalId: "ce2ce14e-85d7-4629-bdbc-454d0519d987",
        principalType: azure_native.authorization.PrincipalType.User,
        roleAssignmentName: "05c5a614-a7d6-4502-b150-c2fb455033ff",
        roleDefinitionId: "/subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d",
        scope: "subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2",
    });
    
    import pulumi
    import pulumi_azure_native as azure_native
    
    role_assignment = azure_native.authorization.RoleAssignment("roleAssignment",
        principal_id="ce2ce14e-85d7-4629-bdbc-454d0519d987",
        principal_type=azure_native.authorization.PrincipalType.USER,
        role_assignment_name="05c5a614-a7d6-4502-b150-c2fb455033ff",
        role_definition_id="/subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d",
        scope="subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2")
    
    resources:
      roleAssignment:
        type: azure-native:authorization:RoleAssignment
        properties:
          principalId: ce2ce14e-85d7-4629-bdbc-454d0519d987
          principalType: User
          roleAssignmentName: 05c5a614-a7d6-4502-b150-c2fb455033ff
          roleDefinitionId: /subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2/providers/Microsoft.Authorization/roleDefinitions/0b5fe924-9a61-425c-96af-cfe6e287ca2d
          scope: subscriptions/a925f2f7-5c63-4b7b-8799-25a5f97bc3b2
    

    Create RoleAssignment Resource

    Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.

    Constructor syntax

    new RoleAssignment(name: string, args: RoleAssignmentArgs, opts?: CustomResourceOptions);
    @overload
    def RoleAssignment(resource_name: str,
                       args: RoleAssignmentArgs,
                       opts: Optional[ResourceOptions] = None)
    
    @overload
    def RoleAssignment(resource_name: str,
                       opts: Optional[ResourceOptions] = None,
                       principal_id: Optional[str] = None,
                       role_definition_id: Optional[str] = None,
                       scope: Optional[str] = None,
                       condition: Optional[str] = None,
                       condition_version: Optional[str] = None,
                       delegated_managed_identity_resource_id: Optional[str] = None,
                       description: Optional[str] = None,
                       principal_type: Optional[Union[str, PrincipalType]] = None,
                       role_assignment_name: Optional[str] = None)
    func NewRoleAssignment(ctx *Context, name string, args RoleAssignmentArgs, opts ...ResourceOption) (*RoleAssignment, error)
    public RoleAssignment(string name, RoleAssignmentArgs args, CustomResourceOptions? opts = null)
    public RoleAssignment(String name, RoleAssignmentArgs args)
    public RoleAssignment(String name, RoleAssignmentArgs args, CustomResourceOptions options)
    
    type: azure-native:authorization:RoleAssignment
    properties: # The arguments to resource properties.
    options: # Bag of options to control resource's behavior.
    
    
    resource "azure-native_authorization_role_assignment" "name" {
        # resource properties
    }

    Parameters

    name string
    The unique name of the resource.
    args RoleAssignmentArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    resource_name str
    The unique name of the resource.
    args RoleAssignmentArgs
    The arguments to resource properties.
    opts ResourceOptions
    Bag of options to control resource's behavior.
    ctx Context
    Context object for the current deployment.
    name string
    The unique name of the resource.
    args RoleAssignmentArgs
    The arguments to resource properties.
    opts ResourceOption
    Bag of options to control resource's behavior.
    name string
    The unique name of the resource.
    args RoleAssignmentArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    name String
    The unique name of the resource.
    args RoleAssignmentArgs
    The arguments to resource properties.
    options CustomResourceOptions
    Bag of options to control resource's behavior.

    Constructor example

    The following reference example uses placeholder values for all input properties.

    var roleAssignmentResource = new AzureNative.Authorization.RoleAssignment("roleAssignmentResource", new()
    {
        PrincipalId = "string",
        RoleDefinitionId = "string",
        Scope = "string",
        Condition = "string",
        ConditionVersion = "string",
        DelegatedManagedIdentityResourceId = "string",
        Description = "string",
        PrincipalType = "string",
        RoleAssignmentName = "string",
    });
    
    example, err := authorization.NewRoleAssignment(ctx, "roleAssignmentResource", &authorization.RoleAssignmentArgs{
    	PrincipalId:                        pulumi.String("string"),
    	RoleDefinitionId:                   pulumi.String("string"),
    	Scope:                              pulumi.String("string"),
    	Condition:                          pulumi.String("string"),
    	ConditionVersion:                   pulumi.String("string"),
    	DelegatedManagedIdentityResourceId: pulumi.String("string"),
    	Description:                        pulumi.String("string"),
    	PrincipalType:                      pulumi.String("string"),
    	RoleAssignmentName:                 pulumi.String("string"),
    })
    
    resource "azure-native_authorization_role_assignment" "roleAssignmentResource" {
      lifecycle {
        create_before_destroy = true
      }
      principal_id                           = "string"
      role_definition_id                     = "string"
      scope                                  = "string"
      condition                              = "string"
      condition_version                      = "string"
      delegated_managed_identity_resource_id = "string"
      description                            = "string"
      principal_type                         = "string"
      role_assignment_name                   = "string"
    }
    
    var roleAssignmentResource = new com.pulumi.azurenative.authorization.RoleAssignment("roleAssignmentResource", com.pulumi.azurenative.authorization.RoleAssignmentArgs.builder()
        .principalId("string")
        .roleDefinitionId("string")
        .scope("string")
        .condition("string")
        .conditionVersion("string")
        .delegatedManagedIdentityResourceId("string")
        .description("string")
        .principalType("string")
        .roleAssignmentName("string")
        .build());
    
    role_assignment_resource = azure_native.authorization.RoleAssignment("roleAssignmentResource",
        principal_id="string",
        role_definition_id="string",
        scope="string",
        condition="string",
        condition_version="string",
        delegated_managed_identity_resource_id="string",
        description="string",
        principal_type="string",
        role_assignment_name="string")
    
    const roleAssignmentResource = new azure_native.authorization.RoleAssignment("roleAssignmentResource", {
        principalId: "string",
        roleDefinitionId: "string",
        scope: "string",
        condition: "string",
        conditionVersion: "string",
        delegatedManagedIdentityResourceId: "string",
        description: "string",
        principalType: "string",
        roleAssignmentName: "string",
    });
    
    type: azure-native:authorization:RoleAssignment
    properties:
        condition: string
        conditionVersion: string
        delegatedManagedIdentityResourceId: string
        description: string
        principalId: string
        principalType: string
        roleAssignmentName: string
        roleDefinitionId: string
        scope: string
    

    RoleAssignment Resource Properties

    To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.

    Inputs

    In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.

    The RoleAssignment resource accepts the following input properties:

    PrincipalId string
    The principal ID.
    RoleDefinitionId string
    The role definition ID.
    Scope string
    The fully qualified Azure Resource manager identifier of the resource.
    Condition string
    The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'
    ConditionVersion string
    Version of the condition. Currently the only accepted value is '2.0'
    DelegatedManagedIdentityResourceId string
    Id of the delegated managed identity resource
    Description string
    Description of role assignment
    PrincipalType string | Pulumi.AzureNative.Authorization.PrincipalType
    The principal type of the assigned principal ID.
    RoleAssignmentName string
    The name of the role assignment. It can be any valid GUID.
    PrincipalId string
    The principal ID.
    RoleDefinitionId string
    The role definition ID.
    Scope string
    The fully qualified Azure Resource manager identifier of the resource.
    Condition string
    The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'
    ConditionVersion string
    Version of the condition. Currently the only accepted value is '2.0'
    DelegatedManagedIdentityResourceId string
    Id of the delegated managed identity resource
    Description string
    Description of role assignment
    PrincipalType string | PrincipalType
    The principal type of the assigned principal ID.
    RoleAssignmentName string
    The name of the role assignment. It can be any valid GUID.
    principal_id string
    The principal ID.
    role_definition_id string
    The role definition ID.
    scope string
    The fully qualified Azure Resource manager identifier of the resource.
    condition string
    The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'
    condition_version string
    Version of the condition. Currently the only accepted value is '2.0'
    delegated_managed_identity_resource_id string
    Id of the delegated managed identity resource
    description string
    Description of role assignment
    principal_type string | "User" | "Group" | "ServicePrincipal" | "ForeignGroup" | "Device" | "AgentUser" | "AgentServicePrincipal"
    The principal type of the assigned principal ID.
    role_assignment_name string
    The name of the role assignment. It can be any valid GUID.
    principalId String
    The principal ID.
    roleDefinitionId String
    The role definition ID.
    scope String
    The fully qualified Azure Resource manager identifier of the resource.
    condition String
    The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'
    conditionVersion String
    Version of the condition. Currently the only accepted value is '2.0'
    delegatedManagedIdentityResourceId String
    Id of the delegated managed identity resource
    description String
    Description of role assignment
    principalType String | PrincipalType
    The principal type of the assigned principal ID.
    roleAssignmentName String
    The name of the role assignment. It can be any valid GUID.
    principalId string
    The principal ID.
    roleDefinitionId string
    The role definition ID.
    scope string
    The fully qualified Azure Resource manager identifier of the resource.
    condition string
    The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'
    conditionVersion string
    Version of the condition. Currently the only accepted value is '2.0'
    delegatedManagedIdentityResourceId string
    Id of the delegated managed identity resource
    description string
    Description of role assignment
    principalType string | PrincipalType
    The principal type of the assigned principal ID.
    roleAssignmentName string
    The name of the role assignment. It can be any valid GUID.
    principal_id str
    The principal ID.
    role_definition_id str
    The role definition ID.
    scope str
    The fully qualified Azure Resource manager identifier of the resource.
    condition str
    The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'
    condition_version str
    Version of the condition. Currently the only accepted value is '2.0'
    delegated_managed_identity_resource_id str
    Id of the delegated managed identity resource
    description str
    Description of role assignment
    principal_type str | PrincipalType
    The principal type of the assigned principal ID.
    role_assignment_name str
    The name of the role assignment. It can be any valid GUID.
    principalId String
    The principal ID.
    roleDefinitionId String
    The role definition ID.
    scope String
    The fully qualified Azure Resource manager identifier of the resource.
    condition String
    The conditions on the role assignment. This limits the resources it can be assigned to. e.g.: @Resource[Microsoft.Storage/storageAccounts/blobServices/containers:ContainerName] StringEqualsIgnoreCase 'foo_storage_container'
    conditionVersion String
    Version of the condition. Currently the only accepted value is '2.0'
    delegatedManagedIdentityResourceId String
    Id of the delegated managed identity resource
    description String
    Description of role assignment
    principalType String | "User" | "Group" | "ServicePrincipal" | "ForeignGroup" | "Device" | "AgentUser" | "AgentServicePrincipal"
    The principal type of the assigned principal ID.
    roleAssignmentName String
    The name of the role assignment. It can be any valid GUID.

    Outputs

    All input properties are implicitly available as output properties. Additionally, the RoleAssignment resource produces the following output properties:

    AzureApiVersion string
    The Azure API version of the resource.
    CreatedBy string
    Id of the user who created the assignment
    CreatedOn string
    Time it was created
    Id string
    The provider-assigned unique ID for this managed resource.
    Name string
    The name of the resource
    SystemData Pulumi.AzureNative.Authorization.Outputs.SystemDataResponse
    Azure Resource Manager metadata containing createdBy and modifiedBy information.
    Type string
    The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts"
    UpdatedBy string
    Id of the user who updated the assignment
    UpdatedOn string
    Time it was updated
    AzureApiVersion string
    The Azure API version of the resource.
    CreatedBy string
    Id of the user who created the assignment
    CreatedOn string
    Time it was created
    Id string
    The provider-assigned unique ID for this managed resource.
    Name string
    The name of the resource
    SystemData SystemDataResponse
    Azure Resource Manager metadata containing createdBy and modifiedBy information.
    Type string
    The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts"
    UpdatedBy string
    Id of the user who updated the assignment
    UpdatedOn string
    Time it was updated
    azure_api_version string
    The Azure API version of the resource.
    created_by string
    Id of the user who created the assignment
    created_on string
    Time it was created
    id string
    The provider-assigned unique ID for this managed resource.
    name string
    The name of the resource
    system_data object
    Azure Resource Manager metadata containing createdBy and modifiedBy information.
    type string
    The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts"
    updated_by string
    Id of the user who updated the assignment
    updated_on string
    Time it was updated
    azureApiVersion String
    The Azure API version of the resource.
    createdBy String
    Id of the user who created the assignment
    createdOn String
    Time it was created
    id String
    The provider-assigned unique ID for this managed resource.
    name String
    The name of the resource
    systemData SystemDataResponse
    Azure Resource Manager metadata containing createdBy and modifiedBy information.
    type String
    The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts"
    updatedBy String
    Id of the user who updated the assignment
    updatedOn String
    Time it was updated
    azureApiVersion string
    The Azure API version of the resource.
    createdBy string
    Id of the user who created the assignment
    createdOn string
    Time it was created
    id string
    The provider-assigned unique ID for this managed resource.
    name string
    The name of the resource
    systemData SystemDataResponse
    Azure Resource Manager metadata containing createdBy and modifiedBy information.
    type string
    The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts"
    updatedBy string
    Id of the user who updated the assignment
    updatedOn string
    Time it was updated
    azure_api_version str
    The Azure API version of the resource.
    created_by str
    Id of the user who created the assignment
    created_on str
    Time it was created
    id str
    The provider-assigned unique ID for this managed resource.
    name str
    The name of the resource
    system_data SystemDataResponse
    Azure Resource Manager metadata containing createdBy and modifiedBy information.
    type str
    The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts"
    updated_by str
    Id of the user who updated the assignment
    updated_on str
    Time it was updated
    azureApiVersion String
    The Azure API version of the resource.
    createdBy String
    Id of the user who created the assignment
    createdOn String
    Time it was created
    id String
    The provider-assigned unique ID for this managed resource.
    name String
    The name of the resource
    systemData Property Map
    Azure Resource Manager metadata containing createdBy and modifiedBy information.
    type String
    The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts"
    updatedBy String
    Id of the user who updated the assignment
    updatedOn String
    Time it was updated

    Supporting Types

    PrincipalType, PrincipalTypeArgs

    User
    User User
    Group
    Group Group
    ServicePrincipal
    ServicePrincipal ServicePrincipal
    ForeignGroup
    ForeignGroup ForeignGroup
    Device
    Device Device
    AgentUser
    AgentUser Agent identity derived from a user.
    AgentServicePrincipal
    AgentServicePrincipal Agent identity derived from a service principal.
    PrincipalTypeUser
    User User
    PrincipalTypeGroup
    Group Group
    PrincipalTypeServicePrincipal
    ServicePrincipal ServicePrincipal
    PrincipalTypeForeignGroup
    ForeignGroup ForeignGroup
    PrincipalTypeDevice
    Device Device
    PrincipalTypeAgentUser
    AgentUser Agent identity derived from a user.
    PrincipalTypeAgentServicePrincipal
    AgentServicePrincipal Agent identity derived from a service principal.
    "User"
    User User
    "Group"
    Group Group
    "ServicePrincipal"
    ServicePrincipal ServicePrincipal
    "ForeignGroup"
    ForeignGroup ForeignGroup
    "Device"
    Device Device
    "AgentUser"
    AgentUser Agent identity derived from a user.
    "AgentServicePrincipal"
    AgentServicePrincipal Agent identity derived from a service principal.
    User
    User User
    Group
    Group Group
    ServicePrincipal
    ServicePrincipal ServicePrincipal
    ForeignGroup
    ForeignGroup ForeignGroup
    Device
    Device Device
    AgentUser
    AgentUser Agent identity derived from a user.
    AgentServicePrincipal
    AgentServicePrincipal Agent identity derived from a service principal.
    User
    User User
    Group
    Group Group
    ServicePrincipal
    ServicePrincipal ServicePrincipal
    ForeignGroup
    ForeignGroup ForeignGroup
    Device
    Device Device
    AgentUser
    AgentUser Agent identity derived from a user.
    AgentServicePrincipal
    AgentServicePrincipal Agent identity derived from a service principal.
    USER
    User User
    GROUP
    Group Group
    SERVICE_PRINCIPAL
    ServicePrincipal ServicePrincipal
    FOREIGN_GROUP
    ForeignGroup ForeignGroup
    DEVICE
    Device Device
    AGENT_USER
    AgentUser Agent identity derived from a user.
    AGENT_SERVICE_PRINCIPAL
    AgentServicePrincipal Agent identity derived from a service principal.
    "User"
    User User
    "Group"
    Group Group
    "ServicePrincipal"
    ServicePrincipal ServicePrincipal
    "ForeignGroup"
    ForeignGroup ForeignGroup
    "Device"
    Device Device
    "AgentUser"
    AgentUser Agent identity derived from a user.
    "AgentServicePrincipal"
    AgentServicePrincipal Agent identity derived from a service principal.

    SystemDataResponse, SystemDataResponseArgs

    Metadata pertaining to creation and last modification of the resource.
    CreatedAt string
    The timestamp of resource creation (UTC).
    CreatedBy string
    The identity that created the resource.
    CreatedByType string
    The type of identity that created the resource.
    LastModifiedAt string
    The timestamp of resource last modification (UTC)
    LastModifiedBy string
    The identity that last modified the resource.
    LastModifiedByType string
    The type of identity that last modified the resource.
    CreatedAt string
    The timestamp of resource creation (UTC).
    CreatedBy string
    The identity that created the resource.
    CreatedByType string
    The type of identity that created the resource.
    LastModifiedAt string
    The timestamp of resource last modification (UTC)
    LastModifiedBy string
    The identity that last modified the resource.
    LastModifiedByType string
    The type of identity that last modified the resource.
    created_at string
    The timestamp of resource creation (UTC).
    created_by string
    The identity that created the resource.
    created_by_type string
    The type of identity that created the resource.
    last_modified_at string
    The timestamp of resource last modification (UTC)
    last_modified_by string
    The identity that last modified the resource.
    last_modified_by_type string
    The type of identity that last modified the resource.
    createdAt String
    The timestamp of resource creation (UTC).
    createdBy String
    The identity that created the resource.
    createdByType String
    The type of identity that created the resource.
    lastModifiedAt String
    The timestamp of resource last modification (UTC)
    lastModifiedBy String
    The identity that last modified the resource.
    lastModifiedByType String
    The type of identity that last modified the resource.
    createdAt string
    The timestamp of resource creation (UTC).
    createdBy string
    The identity that created the resource.
    createdByType string
    The type of identity that created the resource.
    lastModifiedAt string
    The timestamp of resource last modification (UTC)
    lastModifiedBy string
    The identity that last modified the resource.
    lastModifiedByType string
    The type of identity that last modified the resource.
    created_at str
    The timestamp of resource creation (UTC).
    created_by str
    The identity that created the resource.
    created_by_type str
    The type of identity that created the resource.
    last_modified_at str
    The timestamp of resource last modification (UTC)
    last_modified_by str
    The identity that last modified the resource.
    last_modified_by_type str
    The type of identity that last modified the resource.
    createdAt String
    The timestamp of resource creation (UTC).
    createdBy String
    The identity that created the resource.
    createdByType String
    The type of identity that created the resource.
    lastModifiedAt String
    The timestamp of resource last modification (UTC)
    lastModifiedBy String
    The identity that last modified the resource.
    lastModifiedByType String
    The type of identity that last modified the resource.

    Import

    An existing resource can be imported using its type token, name, and identifier, e.g.

    $ pulumi import azure-native:authorization:RoleAssignment 05c5a614-a7d6-4502-b150-c2fb455033ff /{scope}/providers/Microsoft.Authorization/roleAssignments/{roleAssignmentName} 
    

    To learn more about importing existing cloud resources, see Importing resources.

    Package Details

    Repository
    Azure Native pulumi/pulumi-azure-native
    License
    Apache-2.0
    azure-native logo
    This is the latest version of Azure Native. Use the Azure Native v2 docs if using the v2 version of this package.
    Viewing docs for Azure Native v3.26.0
    published on Thursday, Aug 13, 2026 by Pulumi

      Try Pulumi Cloud free.
      Your team will thank you.

      Start free trial