Cloud Infrastructure

Azure RBAC Role Reference

Search Azure RBAC built-in roles and concepts including Owner, Contributor, Reader, management vs data plane actions, Managed Identity types, and PIM just-in-time access.

Calculations run locally in your browser

Azure RBAC Role Reference

The Azure RBAC Role Reference covers built-in roles, Actions vs DataActions, role assignment scope, Managed Identity types, and Privileged Identity Management just-in-time access.

• Find the correct built-in role for read-only access to a resource group

• Understand the difference between Actions and DataActions for storage access

• Look up Managed Identity vs service principal for an Azure Function

• Reference PIM configuration for just-in-time owner access to production subscriptions

Cloud NAT Bandwidth Cost Calculator — Calculate NAT Gateway vs NAT instance cost from daily outbound traffic volume.
Open Cloud NAT Bandwidth Cost Calculator →
What does this tool tell you?
The Azure RBAC Role Reference covers built-in roles, Actions vs DataActions, role assignment scope, Managed Identity types, and Privileged Identity Management just-in-time access.
What affects the result most?
Azure built-in roles: Owner, Contributor, Reader, User Access Administrator — scope and permission differences. Role assignment scope: Management Group → Subscription → Resource Group → Resource. Actions vs DataActions: Actions control management plane, DataActions control data plane (e.g. blob read).
How should I use the result?
Use this tool to orient quickly to the concepts, field names, or values you are about to look up in a full specification or vendor documentation. It summarizes the common cases; the authoritative source remains whichever standard or vendor doc defines the values themselves.