who_has_access
Identifies active Azure RBAC role assignments for a resource across inherited and direct scopes, and reports data-plane auth facts like Key Vault policies and SQL admins.
Instructions
Active Azure RBAC role assignments that apply to a resource: on the resource, its parent resources, its resource group, subscription, management groups and root, marked inherited or direct. scope_coverage says per scope whether assignments were collected (a scope that was not collected is unknown, never zero). Each assignment has capabilities computed from the role definition's actions/notActions: assign_roles, write_resource, delete_resource. Also returns data-plane auth facts (Key Vault access policies, SQL Entra admin, ...).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| target | Yes |