Azure Required Permissions
Below is a list of the roles Prisma Cloud DSPM uses to access your Azure environment and the permissions they have. Permissions are used to access different types of data, or perform actions such as creating/deleting virtual machines (VMs), exporting snapshots, etc.
IMPORTANT: If your Azure subscription has any firewall or network restrictions in place, it is imperative to grant access to the following:
Egress Traffic
In order to allow normal communication between Scanner VMs and the Prisma Cloud DSPM components, as well as various CSP services, make sure the following traffic is permitted:
Outbound rule:
Type: HTTPS (Port 443)
Destination: 0.0.0.0/0
Ingress Traffic
Allow incoming traffic from the following Prisma Cloud DSPM's IP addresses to the customer’s cloud environment. This allows for API communication between Prisma Cloud DSPM’s SaaS environments to the customer’s cloud environment:
EU:
52.48.123.3
99.80.210.235
34.247.249.123
US:
54.225.205.121
18.214.146.232
3.93.120.3
Which roles are deployed in Azure?
Orchestrator Subscription:
subscription-scanner - subscription scope, assigned to Managed identity
subscription-orchestrator - subscription scope, assigned to Enterprise App
subscription-reader - subscription scope, assigned to Enterprise App
orchestrator-role - resource-group scope, assigned to Enterprise Application
scanner-role - resource-group scope, assigned to Managed identity
Monitored Subscriptions:
subscription-scanner - subscription scope, assigned to Managed identity
subscription-orchestrator - subscription scope, assigned to Enterprise App
subscription-reader - subscription scope, assigned to Enterprise App
monitored-role - resource-group scope, assigned to Enterprise Application
Tenant level
Enterprise application with applications.read and user.read permissions
There is also an additional role (Dig-onboarding-monitoring-role) at the management group level when onboarding in a management group scope, with the following details:
Dig-Onboarding-Monitoring-Role
This role is assigned to the Enterprise Application and scoped to the entire monitored management group.
Permission
Scope
Purpose
Microsoft.Management/managementGroups/read
The monitored management group
Used for monitoring onboarded and new management groups
Microsoft.Management/managementGroups/subscriptions/read
The monitored management group
Used for monitoring onboarded and new subscriptions
Prisma Cloud DSPM Roles and permissions
Dig-Security-Subscription-Reader-Role
Used as a read-only access to your environment, this role enables Prisma Cloud DSPM to:
Access your assets’ metadata such as size, name and region
Collect activity logs for DDR capabilities
This role is installed on every subscription monitored by Prisma Cloud DSPM, allowing us to discover and protect your assets. Prisma Cloud DSPM’s own environment performs the read-only API calls using the enterprise application.
This role is assigned to the Enterprise Application and scoped to the entire monitored subscription.
Permissions
Permission
Scope
Purpose
*/read
Monitored subscription
Read-only access, used to get metadata of all managed data assets in the subscription
Microsoft.CognitiveServices/*/read
Monitored subscription
Discovery of OpenAI resources and other Azure AI services
Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read
Monitored subscription
Reading metadata from blobs
Microsoft.Storage/storageAccounts/blobServices/generateUserDelegationKey/action
Monitored subscription
Getting SAS token of blobServices to enable access
Microsoft.Storage/storageAccounts/fileServices/fileshares/files/read
Monitored subscription
Reading metadata from file shares
Microsoft.Storage/storageAccounts/tableServices/tables/entities/read
Monitored subscription
Reading metadata from tables
Microsoft.Web/sites/config/list/action
Monitored subscription
Discovery and Risk assessment of Azure Web App
Dig-Security-Scanner-Role
This role is assigned to Prisma Cloud DSPM’s resource groups in the orchestrator subscriptions in your environment. It can be used only by a local managed identity in your subscription. This enables Prisma Cloud DSPM to detect and scan data for analysis and classification.
All sensitive data that is detected, scanned and classified by Prisma Cloud DSPM’s resources never leaves the client's environment.
This role is assigned to the Managed Identity and scoped to the Prisma Cloud DSPM’s Resource Group in the Orchestrator subscription.
Permissions
Permission
Scope
Purpose
Microsoft.Insights/alertRules/*
Prisma Cloud DSPM’s resource group
Getting metrics on Prisma Cloud DSPM resources
Microsoft.Insights/diagnosticSettings/*
Prisma Cloud DSPM’s resource group
Getting metrics on Prisma Cloud DSPM resources
Microsoft.Network/privateDnsZones/join/action
Prisma Cloud DSPM’s resource group
Assigning private endpoint to DNS zones
Microsoft.Network/privateEndpoints/delete
Prisma Cloud DSPM’s resource group
Deleting private endpoints
Microsoft.Network/privateEndpoints/privateDnsZoneGroups/write
Prisma Cloud DSPM’s resource group
Creating private DNS zones
Microsoft.Network/privateEndpoints/write
Prisma Cloud DSPM’s resource group
Creating private endpoints
Microsoft.Network/virtualNetworks/subnets/join/action
Prisma Cloud DSPM’s resource group
Assigning a private endpoint to a virtual network
Microsoft.Network/virtualNetworks/subnets/joinViaServiceEndpoint/action
Prisma Cloud DSPM’s resource group
Assigning a private endpoint to a virtual network
Microsoft.Resources/deployments/*
Prisma Cloud DSPM’s resource group
Monitoring deployments
Microsoft.Storage/storageAccounts/*
Prisma Cloud DSPM’s resource group
Creating audit storage accounts
Microsoft.Storage/storageAccounts/blobServices/containers/blobs/add/action
Prisma Cloud DSPM’s resource group
Editing logs and reports in the audit storage account
Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete
Prisma Cloud DSPM’s resource group
Deleting blobs in the audit storage account
Microsoft.Storage/storageAccounts/blobServices/containers/blobs/move/action
Prisma Cloud DSPM’s resource group
Editing logs and reports in the audit storage account
Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read
Prisma Cloud DSPM’s resource group
Reading blobs in the audit storage account
Microsoft.Storage/storageAccounts/blobServices/containers/blobs/write
Prisma Cloud DSPM’s resource group
Writing logs and reports in the audit storage account
Microsoft.Storage/storageAccounts/blobServices/containers/delete
Prisma Cloud DSPM’s resource group
Deleting old blobs in the audit storage account
Microsoft.Storage/storageAccounts/blobServices/containers/write
Prisma Cloud DSPM’s resource group
Creating new containers in the audit storage account
Microsoft.Storage/storageAccounts/blobServices/generateUserDelegationKey/action
Prisma Cloud DSPM’s resource group
Getting access SAS token to the storage account
Microsoft.documentdb/databaseaccounts/PrivateEndpointConnectionsApproval/action
Monitored subscription
Used for setting up a private endpoint on Cosmos DBs. This step is crucial for CosmosDB scanning
Dig-Security-Subscription-Scanner-Role
This role is installed on all the scanned (monitored) subscriptions in your environment. It can be used only by a local managed identity in your subscription. This enables Prisma Cloud DSPM to detect and scan data for analysis and classification.
All sensitive data that is detected, scanned and classified by Prisma Cloud DSPM’s resources never leaves the client's environment.
This role is assigned to the Managed Identity and scoped to the entire monitored subscription.
Permissions
Permission
Scope
Purpose
*/read
Monitored subscription
Read-only access, used to get metadata of all managed data assets in the subscription
Microsoft.CognitiveServices/*/action
Monitored subscription
Reading and scanning OpenAI files and other Azure AI data resources
Microsoft.CognitiveServices/*/read
Monitored subscription
Monitoring AI deployments
Microsoft.DocumentDB/databaseAccounts/listKeys/*
Monitored subscription
Getting SAS token of CosmosDB to enable access
Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read
Monitored subscription
Assigning a private endpoint to a virtual network
Microsoft.Storage/storageAccounts/blobServices/generateUserDelegationKey/action
Monitored subscription
Getting SAS token of blobServices to enable access
Microsoft.Storage/storageAccounts/fileServices/fileshares/files/read
Monitored subscription
Scanning file shares
Microsoft.Storage/storageAccounts/ListAccountSas/action
Monitored subscription
Getting access SAS token to the storage account to scan file share instances using API
Microsoft.Storage/storageAccounts/listKeys/action
Monitored subscription
Getting access key to the storage account to scan file share instances using API
Microsoft.Storage/storageAccounts/PrivateEndpointConnectionsApproval/action
Monitored subscription
Enabling a scan by assigning private endpoints to a storage account located in a private network
Microsoft.Storage/storageAccounts/tableServices/tables/entities/read
Monitored subscription
Scanning tables
Dig-Security-Subscription-Orchestrator-Role
These permissions are installed on all monitored subscriptions in your environment. This role enables Prisma Cloud DSPM to classify and scan data assets and analyze them in Prisma Cloud DSPM’s resource group.
All sensitive data that is detected, scanned and classified by Prisma Cloud DSPM’s resources never leaves the client's environment.
This role is assigned to the Enterprise Application and scoped to the entire monitored subscription.
Permissions
Permission
Scope
Purpose
Microsoft.documentdb/databaseaccounts/PrivateEndpointConnectionsApproval/action
Monitored subscription
Used for setting up a private endpoint on Cosmos DBs. This step is crucial for CosmosDB scanning
Microsoft.Sql/managedInstances/databases/readBackups/action
Monitored subscription
Used for copying SQL managed instances to Prisma Cloud DSPM’s resource group, enabling Prisma Cloud DSPM to connect and scan it
Microsoft.Sql/managedInstances/databases/write
Monitored subscription
Used for copying PITR of SQL managed instances to Prisma Cloud DSPM’s resource group, enabling Prisma Cloud DSPM to restore and scan it
Microsoft.Sql/servers/databases/write
Monitored subscription
Used for copying SQL databases to Prisma Cloud DSPM’s resource group, enabling Prisma Cloud DSPM to connect and scan it
Dig-Security-Monitored-Role
These permissions are installed on all Prisma Cloud DSPM’s resource groups in all monitored subscriptions except the orchestrator. This role is used for creating temporary resources inside Prisma Cloud DSPM’s resource group only.
This role is assigned to the Enterprise Application and scoped to the Prisma Cloud DSPM’s Resource Group in the Monitored subscription.
Permission
Permission
Scope
Purpose
Microsoft.Compute/disks/beginGetAccess/action
Prisma Cloud DSPM’s resource group
Enabling access to the disk data for creating disks from snapshots
Microsoft.Compute/disks/delete
Prisma Cloud DSPM’s resource group
Deleting created disks
Microsoft.Compute/disks/write
Prisma Cloud DSPM’s resource group
Creating and modifying snapshots of the scanned disks
Microsoft.Compute/snapshots/delete
Prisma Cloud DSPM’s resource group
Deleting scanned snapshots
Microsoft.Compute/snapshots/write
Prisma Cloud DSPM’s resource group
Creating and modifying snapshots for scanning
Microsoft.ManagedIdentity/userAssignedIdentities/assign/action
Prisma Cloud DSPM’s resource group only
Assigning a managed identity to the created VM
Microsoft.Network/natGateways/join/action
Prisma Cloud DSPM’s resource group
Associating NAT gateways with the created VMs
Microsoft.Network/natGateways/write
Prisma Cloud DSPM’s resource group
Creating and modifying NAT gateways
Microsoft.Network/networkInterfaces/delete
Prisma Cloud DSPM’s resource group
Deleting created network interfaces
Microsoft.Network/networkInterfaces/join/action
Prisma Cloud DSPM’s resource group
Associating the created network interface with a virtual machine
Microsoft.Network/networkInterfaces/write
Prisma Cloud DSPM’s resource group
Creating and modifying network interfaces to ensure that the created VMs have outbound internet access
Microsoft.Network/networkSecurityGroups/delete
Prisma Cloud DSPM’s resource group
Deleting created security groups
Microsoft.Network/networkSecurityGroups/join/action
Prisma Cloud DSPM’s resource group
Associating the created security group with a subnet or network interface
Microsoft.Network/networkSecurityGroups/write
Prisma Cloud DSPM’s resource group
Creating and modifying security groups to ensure that Prisma Cloud DSPM’s VMs cannot be reached and secured
Microsoft.Network/privateDnsZones/delete
Prisma Cloud DSPM’s resource group
Setting private DNS zones to classify private resource
Microsoft.Network/privateDnsZones/join/action
Prisma Cloud DSPM’s resource group
Setting private DNS zones to classify private resource
Microsoft.Network/privateDnsZones/virtualNetworkLinks/write
Prisma Cloud DSPM’s resource group
Setting private DNS zones to classify private resource
Microsoft.Network/privateDnsZones/write
Prisma Cloud DSPM’s resource group
Setting private DNS zones to classify private resource
Microsoft.Network/privateEndpoints/delete
Prisma Cloud DSPM’s resource group
Deleting unused private endpoints
Microsoft.Network/privateEndpoints/privateDnsZoneGroups/delete
Prisma Cloud DSPM’s resource group
Setting private endpoints to classify private resource
Microsoft.Network/privateEndpoints/privateDnsZoneGroups/write
Prisma Cloud DSPM’s resource group
Setting private endpoints to classify private resource
Microsoft.Network/privateEndpoints/write
Prisma Cloud DSPM’s resource group
Setting private endpoints to classify private resource
Microsoft.Network/routeTables/*
Prisma Cloud DSPM’s resource group
Routing internal traffic
Microsoft.Network/virtualNetworks/delete
Prisma Cloud DSPM’s resource group
Deleting created virtual networks
Microsoft.Network/virtualNetworks/join/action
Prisma Cloud DSPM’s resource group
Connect subnet to the Prisma Cloud Resources
Microsoft.Network/virtualNetworks/subnets/delete
Prisma Cloud DSPM’s resource group
Connect subnet to the Prisma Cloud Resources
Microsoft.Network/virtualNetworks/subnets/join/action
Prisma Cloud DSPM’s resource group
Associating virtual networks with the created VMs
Microsoft.Network/virtualNetworks/subnets/joinViaServiceEndpoint/action
Prisma Cloud DSPM’s resource group
Assigning a private endpoint to a virtual network
Microsoft.Network/virtualNetworks/subnets/write
Prisma Cloud DSPM’s resource group only
Creating and modifying subnets inside the virtual network
Microsoft.Network/virtualNetworks/write
Prisma Cloud DSPM’s resource group
Creating and modifying a virtual network so that the created virtual machines
Microsoft.Resources/deployments/write
Prisma Cloud DSPM’s resource group
Deploying resources to a resource group
Microsoft.Sql/locations/*/read
Prisma Cloud DSPM’s resource group
Used for classification of managed instances
Microsoft.Sql/managedInstances/*
Prisma Cloud DSPM’s resource group
Used for classification of managed instances
Microsoft.Sql/servers/databases/delete
Prisma Cloud DSPM’s resource group
Cleaning stale assets such as Prisma Cloud DSPM’s Azure SQL databases - only in the Orchestrator resource group
Microsoft.Sql/servers/databases/move/action
Prisma Cloud DSPM’s resource group
Creating and managing Prisma Cloud DSPM’s Azure SQL databases in the Orchestrator resource group
Microsoft.Sql/servers/databases/read
Prisma Cloud DSPM’s resource group
Getting configurations on Prisma Cloud DSPM’s Azure SQL databases - only in the Orchestrator resource group
Microsoft.Sql/servers/databases/write
Prisma Cloud DSPM’s resource group
Copying and managing SQL databases in Prisma Cloud DSPM’s Azure SQL server in the Orchestrator resource group
Microsoft.Sql/servers/delete
Prisma Cloud DSPM’s resource group
Cleaning stale assets such as Prisma Cloud DSPM’s Azure SQL server - only in the Orchestrator resource group
Microsoft.Sql/servers/encryptionProtector/*
Prisma Cloud DSPM’s resource group
Required in order to classify SQL servers encrypted with server-level TDE
Microsoft.Sql/servers/privateEndpointConnectionsApproval/action
Prisma Cloud DSPM’s resource group
Enables connection using endpoints
Microsoft.Sql/servers/read
Prisma Cloud DSPM’s resource group
Getting configurations on Prisma Cloud DSPM’s Azure SQL server - only in the Orchestrator resource group
Microsoft.Sql/servers/virtualNetworkRules/*
Prisma Cloud DSPM’s resource group
Configuring network accessibility from the scanning VMs on Prisma Cloud DSPM’s Azure SQL server - only in the Orchestrator resource group
Microsoft.Sql/servers/write
Prisma Cloud DSPM’s resource group
Creating and managing Prisma Cloud DSPM’s Azure SQL server in the orchestrator resource group
Dig-Security-Orchestrator-Role
These permissions are installed on Prisma Cloud DSPM’s resource-group within the orchestrator subscription. This role is used for deploying Prisma Cloud DSPM’s compute resources (VMs) that scan and analyze the monitored subscription. Each VM is assigned with scanner permissions so that it can access, scan and analyze the data.
All sensitive data that is detected, scanned and classified by Prisma Cloud DSPM’s resources never leaves the client's environment.
This role is assigned to the Enterprise Application and scoped to the Prisma Cloud DSPM’s Resource Group in the Orchestrator subscription.
Permissions
Permission
Scope
Purpose
Microsoft.Compute/disks/beginGetAccess/action
Prisma Cloud DSPM’s resource group
Enabling access to the disk data for creating disks from snapshots
Microsoft.Compute/disks/delete
Prisma Cloud DSPM’s resource group
Deleting created disks
Microsoft.Compute/disks/write
Prisma Cloud DSPM’s resource group
Creating and modifying snapshots of the scanned disks
Microsoft.Compute/snapshots/delete
Prisma Cloud DSPM’s resource group
Deleting scanned snapshots
Microsoft.Compute/snapshots/write
Prisma Cloud DSPM’s resource group
Creating and modifying snapshots for scanning
Microsoft.Compute/virtualMachines/delete
Prisma Cloud DSPM’s resource group
Deleting scanner virtual machines (VMs)
Microsoft.Compute/virtualMachines/write
Prisma Cloud DSPM’s resource group
Creating and modifying VMs and attaching disks
Microsoft.EventHub/*
Prisma Cloud DSPM’s resource group
Permissions to manage Prisma Cloud DSPM’s Event Hub for DDR capabilities
Microsoft.EventHub/*/receive/action
Monitored subscription
Reading activity logs from Dig-Security event hub
Microsoft.KeyVault/vaults/write
Prisma Cloud DSPM’s resource group
Create Vault for saving secrets as part of scanning services that requires password creation
Microsoft.ManagedIdentity/userAssignedIdentities/assign/action
Prisma Cloud DSPM’s resource group only
Assigning a managed identity to the created VM
Microsoft.Network/natGateways/delete
Prisma Cloud DSPM’s resource group
Deleting NAT gateways
Microsoft.Network/natGateways/join/action
Prisma Cloud DSPM’s resource group
Associating NAT gateways with the created VMs
Microsoft.Network/natGateways/write
Prisma Cloud DSPM’s resource group
Creating and modifying NAT gateways
Microsoft.Network/networkInterfaces/delete
Prisma Cloud DSPM’s resource group
Deleting created network interfaces
Microsoft.Network/networkInterfaces/join/action
Prisma Cloud DSPM’s resource group
Associating the created network interface with a virtual machine
Microsoft.Network/networkInterfaces/write
Prisma Cloud DSPM’s resource group
Creating and modifying network interfaces to ensure that the created VMs have outbound internet access
Microsoft.Network/networkSecurityGroups/delete
Prisma Cloud DSPM’s resource group
Deleting created security groups
Microsoft.Network/networkSecurityGroups/join/action
Prisma Cloud DSPM’s resource group
Associating the created security group with a subnet or network interface
Microsoft.Network/networkSecurityGroups/securityRules/write
Prisma Cloud DSPM’s resource group
Modifying the Network Security Group (NSG) to establish an outgoing connection over SMB (port 445) with on-prem file shares for classification purposes
Microsoft.Network/networkSecurityGroups/write
Prisma Cloud DSPM’s resource group
Creating and modifying security groups to ensure that Prisma Cloud DSPM’s VMs cannot be reached and secured
Microsoft.Network/privateDnsZones/A/write
Prisma Cloud DSPM’s resource group
Permissions to add privateDNS zone as part of the SQL Managed Instance scanning
Microsoft.Network/privateDnsZones/delete
Prisma Cloud DSPM’s resource group
Setting private DNS zones to classify private resource
Microsoft.Network/privateDnsZones/join/actionMicrosoft.Storage/storageAccounts/blobServices/containers/blobs/read
Prisma Cloud DSPM’s resource group
Setting private DNS zones to classify private resource
Microsoft.Network/privateDnsZones/virtualNetworkLinks/delete
Prisma Cloud DSPM’s resource group
Setting private DNS zones to classify private resource
Microsoft.Network/privateDnsZones/virtualNetworkLinks/write
Prisma Cloud DSPM’s resource group
Setting private DNS zones to classify private resource
Microsoft.Network/privateDnsZones/write
Prisma Cloud DSPM’s resource group
Setting private DNS zones to classify private resource
Microsoft.Network/privateEndpoints/privateDnsZoneGroups/delete
Prisma Cloud DSPM’s resource group
Setting private endpoints to classify private resource
Microsoft.Network/privateEndpoints/privateDnsZoneGroups/write
Prisma Cloud DSPM’s resource group
Setting private endpoints to classify private resource
Microsoft.Network/privateEndpoints/write
Prisma Cloud DSPM’s resource group
Setting private endpoints to classify private resource
Microsoft.Network/publicIPAddresses/delete
Prisma Cloud DSPM’s resource group only
Deleting the public IP address
Microsoft.Network/publicIPAddresses/join/action
Prisma Cloud DSPM’s resource group only
Associating the created public IP
Microsoft.Network/publicIPAddresses/write
Prisma Cloud DSPM’s resource group only
Creating and modifying the public IP address
Microsoft.Network/virtualNetworks/delete
Prisma Cloud DSPM’s resource group
Deleting created virtual networks
Microsoft.Network/virtualNetworks/join/action
Prisma Cloud DSPM’s resource group
Connect subnet to the Prisma Cloud Resources
Microsoft.Network/virtualNetworks/subnets/delete
Prisma Cloud DSPM’s resource group
Assigning a private endpoint to a virtual network
Microsoft.Network/virtualNetworks/subnets/join/action
Prisma Cloud DSPM’s resource group
Associating virtual networks with the created VMs
Microsoft.Network/virtualNetworks/subnets/joinViaServiceEndpoint/action
Prisma Cloud DSPM’s resource group
Assigning a private endpoint to a virtual network
Microsoft.Network/virtualNetworks/subnets/write
Prisma Cloud DSPM’s resource group only
Creating and modifying subnets inside the virtual network
Microsoft.Network/virtualNetworks/write
Prisma Cloud DSPM’s resource group
Creating and modifying a virtual network so that the created virtual machines
Microsoft.Resources/deployments/write
Prisma Cloud DSPM’s resource group
Deploying resources to a resource group
Microsoft.Sql/servers/administrators/delete
Prisma Cloud DSPM’s resource group
Used for classification of SQL Server
Microsoft.Sql/servers/administrators/read
Prisma Cloud DSPM’s resource group
Used for classification of SQL Server
Microsoft.Sql/servers/administrators/write
Prisma Cloud DSPM’s resource group
Used for classification of SQL Server
Microsoft.Sql/servers/databases/*
Prisma Cloud DSPM’s resource group
Creating and managing Prisma Cloud DSPM’s Azure SQL databases in the Orchestrator resource group
Microsoft.Sql/servers/delete
Prisma Cloud DSPM’s resource group
Cleaning stale assets such as Prisma Cloud DSPM’s Azure SQL server - only in the Orchestrator resource group
Microsoft.Sql/servers/encryptionProtector/*
Prisma Cloud DSPM’s resource group
Required in order to classify SQL servers encrypted with server-level TDE
Microsoft.Sql/servers/read
Prisma Cloud DSPM’s resource group
Getting configurations on Prisma Cloud DSPM’s Azure SQL server - only in the Orchestrator resource group
Microsoft.Sql/servers/virtualNetworkRules/*
Prisma Cloud DSPM’s resource group
Configuring network accessibility from the scanning VMs on Prisma Cloud DSPM’s Azure SQL server - only in the Orchestrator resource group
Microsoft.Sql/servers/write
Prisma Cloud DSPM’s resource group
Creating and managing Prisma Cloud DSPM’s Azure SQL server in the orchestrator resource group
Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete
Prisma Cloud DSPM’s resource group
Deleting blobs in the audit storage account
Microsoft.Storage/storageAccounts/blobServices/containers/blobs/write
Prisma Cloud DSPM’s resource group
Writing logs and reports in the audit storage account
Microsoft.Storage/storageAccounts/blobServices/containers/delete
Prisma Cloud DSPM’s resource group
Deleting old blobs in the audit storage account
Microsoft.Storage/storageAccounts/blobServices/containers/write
Prisma Cloud DSPM’s resource group
Creating new containers in the audit storage account
Microsoft.Storage/storageAccounts/blobServices/write
Prisma Cloud DSPM’s resource group
Writing data into the audit storage account
Microsoft.Storage/storageAccounts/delete
Prisma Cloud DSPM’s resource group
Deleting an audit storage account
Microsoft.Storage/storageAccounts/managementPolicies/delete
Prisma Cloud DSPM’s resource group
Permissions for deleting a lifecycle policy on Prisma Cloud DSPM’s storage accounts
Microsoft.Storage/storageAccounts/managementPolicies/write
Prisma Cloud DSPM’s resource group
Permissions for adding a lifecycle policy on Prisma Cloud DSPM’s storage accounts
Microsoft.Storage/storageAccounts/write
Prisma Cloud DSPM’s resource group
Creating an audit storage account
Note: For additional details about the architecture of Prisma Cloud DSPM, please consult with your account team.
Last updated
Was this helpful?

