slug: microsoft-azure provider: Microsoft Azure generated_by: planning/capability-mapping/scripts/classify_capabilities.py model: claude-opus-5 frame: - Banking & Capital Markets - Software & Technology min_confidence: 0.7 capability_model: source: https://github.com/vincentmakes/turbo-ea-capabilities license: CC-BY-4.0 attribution: Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0 notice: NOTICE edge_count: 375 edges: - tag: GetAccessReviewDefaultSettings spec_file: microsoft-azure-getaccessreviewdefaultsettings-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.9 evidence: accessReviewScheduleSettings/default; schemas AccessReviewDefaultSettings, AccessReviewRecurrenceSettings reason: Configures default recurrence settings for Azure AD access reviews under Microsoft.Authorization — access certification/recertification, a core Identity & Access Management activity. - tag: GetAccessReviewHistoryDefinition spec_file: microsoft-azure-getaccessreviewhistorydefinition-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.9 evidence: accessReviewHistoryDefinitions/{historyDefinitionId}; AccessReviewHistoryDefinitionProperties, AccessReviewScope reason: Retrieves access review history definitions under Microsoft.Authorization — access review/certification reporting within Identity & Access Management. - tag: GetAccessReviewHistoryDefinitionInstances spec_file: microsoft-azure-getaccessreviewhistorydefinitioninstances-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.9 evidence: accessReviewHistoryDefinitions/{historyDefinitionId}/instances; AccessReviewHistoryDefinitionInstanceListResult reason: Lists instances of access review history definitions — access certification reporting, part of Identity & Access Management. - tag: GetAccessReviewHistoryDefinitions spec_file: microsoft-azure-getaccessreviewhistorydefinitions-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.9 evidence: Get Subscriptions Subscriptionid Providers Microsoft Authorization Accessreviewhistorydefinitions; AccessReviewHistoryDefinitionListResult reason: Lists access review history definitions for a subscription — access review/certification administration under IAM. - tag: GetAccessReviewInstance spec_file: microsoft-azure-getaccessreviewinstance-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.9 evidence: accessReviewScheduleDefinitions/{scheduleDefinitionId}/instances/{id}; AccessReviewInstanceProperties, AccessReviewReviewer reason: Retrieves a scheduled access review instance including reviewers — access recertification within Identity & Access Management. - tag: GetAccessReviewInstanceDecisions spec_file: microsoft-azure-getaccessreviewinstancedecisions-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.9 evidence: instances/{id}/decisions; AccessReviewDecisionResource, AccessReviewDecisionIdentity reason: Lists approve/deny decisions on access review instances — access recertification decisions, core Identity & Access Management. - tag: GetAccessReviewInstances spec_file: microsoft-azure-getaccessreviewinstances-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.9 evidence: accessReviewScheduleDefinitions/{scheduleDefinitionId}/instances; AccessReviewInstanceListResult reason: Lists access review instances for a schedule definition under Microsoft.Authorization — access certification within IAM. - tag: GetAccessReviewInstancesAssignedForMyApproval spec_file: microsoft-azure-getaccessreviewinstancesassignedformyapproval-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.9 evidence: Accessreviewinstancesassignedformyapproval List; AccessReviewInstanceProperties, AccessReviewReviewer reason: Lists access review instances assigned to the caller for approval — reviewer-side access recertification, an IAM capability. - tag: GetAccessReviewMyInstanceDecision spec_file: microsoft-azure-getaccessreviewmyinstancedecision-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.9 evidence: instances/{id}/decisions/{decisionId}; AccessReviewDecisionProperties reason: Retrieves a specific access review decision assigned to the caller — access certification decisioning under Identity & Access Management. - tag: LoadBalancers spec_file: microsoft-azure-load-balancers-api-openapi.yml reanchored_from: microsoft-azure-loadbalancers-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.9 evidence: PUT /subscriptions/.../providers/Microsoft.Network/loadBalancers/{loadBalancerName} microsoftAzureLoadbalancersCreateorupdate reason: CRUD over Microsoft.Network load balancers is management of cloud network infrastructure. - tag: LocalNetworkGateways spec_file: microsoft-azure-localnetworkgateways-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.9 evidence: PUT /subscriptions/.../providers/Microsoft.Network/localNetworkGateways/{localNetworkGatewayName} reason: Managing VPN local network gateway resources is cloud network infrastructure management. - tag: Managed Clusters spec_file: microsoft-azure-managed-clusters-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.9 evidence: description "Operations for managing AKS clusters"; "Create or Update a Managed Cluster"; schema ManagedClusterAgentPoolProfile reason: Kubernetes cluster provisioning, updating, deletion and credential listing — unambiguously compute/cloud infrastructure management. - tag: NetworkInterfaces spec_file: microsoft-azure-network-interfaces-api-openapi.yml reanchored_from: microsoft-azure-networkinterfaces-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.9 evidence: schemas NetworkInterface, NetworkInterfacePropertiesFormat, NetworkInterfaceDnsSettings reason: CRUD over virtual machine network interfaces — plainly cloud network infrastructure management. - tag: P2SVpnGateways spec_file: microsoft-azure-p2svpngateways-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.9 evidence: Microsoft.Network/p2svpnGateways/{gatewayName}/generatevpnprofile ... getP2sVpnConnectionHealth reason: Point-to-site VPN gateway lifecycle and connection health — network infrastructure management. - tag: ReplicationRecoveryPlans spec_file: microsoft-azure-replicationrecoveryplans-api-openapi.yml capability_id: BC-160.20 capability_id_l1: BC-160 capability_name: Disaster Recovery Management confidence: 0.9 evidence: '"Creates A Recovery Plan With The Given Details", "Execute Test Failover Of The Recovery Plan", "Execute Test Failover Cleanup Of The Recovery Plan", "Execute Unplanned Failover Of The Recovery Plan"' reason: Recovery plan authoring plus planned/unplanned/test failover execution is textbook IT disaster recovery, including DR testing. No alternative reading fits. - tag: GetAccessReviewInstanceContactedReviewers spec_file: microsoft-azure-getaccessreviewinstancecontactedreviewers-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.88 evidence: instances/{id}/contactedReviewers; AccessReviewContactedReviewerProperties reason: Lists reviewers contacted for an access review instance — access certification workflow, an IAM governance activity. - tag: ReplicationProtectedItems spec_file: microsoft-azure-replicationprotecteditems-api-openapi.yml capability_id: BC-160.20 capability_id_l1: BC-160 capability_name: Disaster Recovery Management confidence: 0.88 evidence: '"Enables Protection", "Execute Planned Failover", "Execute Commit Failover", "Change Or Apply Recovery Point", schema EnableProtectionInput' reason: Operations enable/disable replication protection for workloads and execute planned/unplanned/commit failover with recovery points — this is squarely IT disaster recovery / failover orchestration, not any business-domain protection concept. - tag: ServicePrincipal spec_file: microsoft-azure-serviceprincipal-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.88 evidence: POST /{tenantID}/servicePrincipals microsoftAzureServiceprincipalsCreate; schemas ServicePrincipalCreateParameters, AppRole, OAuth2Permission, PasswordCredential, KeyCredential reason: CRUD over directory service principals with app roles, OAuth2 permissions and credentials — machine identity administration in a tenant directory, squarely Identity & Access Management. - tag: VmmServers spec_file: microsoft-azure-vmmservers-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.88 evidence: '''Gets A Vmmserver'', ''Implements Vmmservers Put Method''; schemas VMMServer, VMMServerProperties, ExtendedLocation' reason: CRUD over System Center VMM server resources registered in Azure — management of virtualisation/compute infrastructure. - tag: Volume Groups spec_file: microsoft-azure-volume-groups-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.88 evidence: '''Describe All Volume Groups'', ''Create The Specified Volume Group And Volumes'' under Microsoft.NetApp/netAppAccounts' reason: Provisioning of Azure NetApp storage volume groups and volumes — cloud storage infrastructure management. 'Volume/Inventory' wording here is storage, not supply-chain stock. - tag: VolumeGroups spec_file: microsoft-azure-volume-groups-api-openapi.yml reanchored_from: microsoft-azure-volumegroups-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.88 evidence: '"APIs for Volume Group operations" under Microsoft.ElasticSan/elasticSans/{elasticSanName}/volumegroups; schemas VolumeGroup, StorageTargetType, NetworkRuleSet' reason: Lifecycle management of Elastic SAN volume groups — cloud block storage infrastructure resources. - tag: VirtualWANs spec_file: microsoft-azure-virtualwans-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.87 evidence: 'PATCH .../providers/Microsoft.Network/virtualWans/{VirtualWANName}; schemas: VirtualWAN, VirtualHub, VirtualHubRouteTable, HubRoutingPreference' reason: Operations manage Azure virtual WAN and virtual hub network resources with route tables — cloud network infrastructure provisioning, i.e. IT Infrastructure Management. No business-domain capability applies. - tag: ApplicationGateways spec_file: microsoft-azure-application-gateways-api-openapi.yml reanchored_from: microsoft-azure-applicationgateways-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: providers/Microsoft.Network/applicationGateways ... schemas ApplicationGatewayBackendAddressPool, ApplicationGatewayHttpListener, ApplicationGatewaySslCertificate reason: Provisioning and start/stop of Azure Application Gateway network load-balancing resources — clearly network/cloud infrastructure management. - tag: BackupInstances spec_file: microsoft-azure-backupinstances-api-openapi.yml capability_id: BC-4220.60 capability_id_l1: BC-4220 capability_name: Disaster Recovery & Resilience confidence: 0.85 evidence: 'backupInstances/{backupInstanceName}/backup ... /restore; schemas: TriggerBackupRequest, AzureBackupRestoreRequest, ValidateForBackupRequest' reason: Creates protected backup instances and triggers ad-hoc backup, restore, cross-region restore and rehydrate — clearly backup, restore and DR operations. - tag: BackupPolicies spec_file: microsoft-azure-backup-policies-api-openapi.yml reanchored_from: microsoft-azure-backuppolicies-api-openapi.yml capability_id: BC-4220.60 capability_id_l1: BC-4220 capability_name: Disaster Recovery & Resilience confidence: 0.85 evidence: Microsoft Azure Creates Or Updates A Backup Policy Belonging To A Backup Vault; ...backupPolicies/{backupPolicyName}/backup (BackupNow) reason: Defines and manages backup protection policies (schedule/retention) across Data Protection, Recovery Services and StorSimple, including triggering backup now — backup and restore management. - tag: BareMetalInfrastructure spec_file: microsoft-azure-baremetalinfrastructure-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '"Gets A List Of Azure Baremetal Instances In The Specified Subscription"; schemas HardwareProfile, StorageProfile, NetworkProfile, Disk' reason: Lifecycle of bare-metal compute instances with hardware, storage and network profiles — unambiguously compute/infrastructure provisioning (IT Infrastructure Management). - tag: Caches spec_file: microsoft-azure-caches-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: providers/Microsoft.StorageCache/caches ... microsoftAzureCachesCreateorupdate, Caches Cachename Flush, Start, Stop; schemas CacheNetworkSettings, CacheHealth, StorageTargetSpaceAllocation reason: Provisioning and operating Azure Storage Cache resources — storage/compute infrastructure lifecycle. Cleanly IT Infrastructure Management; no business-domain reading applies. - tag: Capacity Pools spec_file: microsoft-azure-capacity-pools-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: Microsoft Azure Create Or Update The Specified Capacity Pool Within The Resource Group; providers/Microsoft.NetApp/netAppAccounts/{accountName}/capacityPools; schemas capacityPool, poolProperties, serviceLevel reason: Lifecycle management of Azure NetApp Files capacity pools — storage infrastructure provisioning with service levels. Clearly IT Infrastructure Management. - tag: 'Custom Speech Models:' spec_file: microsoft-azure-custom-speech-models-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.85 evidence: POST /models "Creates A New Model"; GET /models/base "Gets The List Of Base Models"; schemas CustomModel, ModelManifest, ModelDeprecationDates reason: Direct management of custom and base ML model artefacts including creation, copying, manifests and deprecation dates — AI/ML model lifecycle management. - tag: DedicatedCloudNodes spec_file: microsoft-azure-dedicatedcloudnodes-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '"dedicated cloud nodes operations"; "Implements Dedicated Cloud Node Put Method" under Microsoft.VMwareCloudSimple' reason: Provisioning and lifecycle of dedicated compute nodes in VMware Cloud Simple — plainly compute infrastructure management. - tag: DnsForwardingRulesets spec_file: microsoft-azure-dnsforwardingrulesets-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: 'PUT /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Network/dnsForwardingRulesets/{dnsForwardingRulesetName} ... schemas: DnsForwardingRuleset, VirtualNetworkLinkSubResourceProperties' reason: CRUD over Azure Network DNS forwarding rulesets linked to virtual networks — cloud network infrastructure provisioning, i.e. IT Infrastructure Management. - tag: DnsResolvers spec_file: microsoft-azure-dnsresolvers-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: 'providers/Microsoft.Network/dnsResolvers/{dnsResolverName} ... schemas: DnsResolver, DnsResolverProperties' reason: Lifecycle management of Azure private DNS resolver network resources — cloud/network infrastructure management. - tag: ExpressRouteCircuitPeerings spec_file: microsoft-azure-expressroutecircuitpeerings-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: PUT .../Microsoft.Network/expressRouteCircuits/{circuitName}/peerings/{peeringName}; schemas ExpressRouteCircuitPeeringConfig, ExpressRouteCircuitStats reason: CRUD over BGP peering configuration on ExpressRoute circuits — clearly network infrastructure management. - tag: ExpressRouteCircuits spec_file: microsoft-azure-expressroute-circuits-api-openapi.yml reanchored_from: microsoft-azure-expressroutecircuits-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: GET .../expressRouteCircuits/{circuitName}arpTable and routesTable; schemas ExpressRouteCircuitSku, ExpressRouteCircuitServiceProviderProperties reason: Lifecycle and diagnostics of dedicated private network circuits (ARP tables, route tables, stats) — cloud network infrastructure management. - tag: ExpressRouteConnections spec_file: microsoft-azure-expressrouteconnections-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: PUT .../expressRouteGateways/{expressRouteGatewayName}/expressRouteConnections/{connectionName}; schemas RoutingConfiguration, PropagatedRouteTable, VnetRoute reason: Creates and manages connections between ExpressRoute gateways and circuits with routing configuration — network infrastructure management. - tag: GetAccessReviewMyInstanceDecisions spec_file: microsoft-azure-getaccessreviewmyinstancedecisions-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: GET /providers/Microsoft.Authorization/accessReviewScheduleDefinitions/{scheduleDefinitionId}/instances/{id}/decisions; schemas AccessReviewDecisionResource, AccessReviewDecisionIdentity reason: Operations retrieve reviewer decisions for Azure access reviews under Microsoft.Authorization — access certification/recertification, a core Identity & Access Management activity. - tag: GetAccessReviewScheduleDefinition spec_file: microsoft-azure-getaccessreviewscheduledefinition-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: accessReviewScheduleDefinitions/{scheduleDefinitionId}; schemas AccessReviewScheduleDefinition, AccessReviewReviewer, AccessReviewScope reason: Retrieves the definition of a recurring access review (scope, reviewers, recurrence) under the Authorization provider — identity governance / access certification, part of IAM. - tag: GetAccessReviewScheduleDefinitions spec_file: microsoft-azure-getaccessreviewscheduledefinitions-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: microsoftAzureAccessreviewscheduledefinitionsList over /providers/Microsoft.Authorization/accessReviewScheduleDefinitions with AccessReviewReviewer, AccessReviewScope reason: Listing access review schedule definitions is access certification administration within Identity & Access Management, not a business-domain review process. - tag: GetAccessReviewScheduleDefinitionsAssignedForMyApproval spec_file: microsoft-azure-getaccessreviewscheduledefinitionsassignedformyapproval-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: Accessreviewscheduledefinitionsassignedformyapproval List; schemas AccessReviewReviewer, AccessReviewScope, AccessReviewInstance reason: Surfaces access reviews assigned to the caller as reviewer/approver — access recertification workflow, an IAM governance capability. - tag: GlobalReachConnections spec_file: microsoft-azure-globalreachconnections-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '"List Global Reach Connections In A Private Cloud"; "Create Or Update A Global Reach Connection In A Private Cloud"; schema GlobalReachConnectionProperties under Microsoft.AVS/privateClouds' reason: ExpressRoute Global Reach connections for Azure VMware private clouds are pure network connectivity provisioning — compute/network/cloud infrastructure management. No business-domain reading is plausible. - tag: HyperDriveExperiment spec_file: microsoft-azure-hyperdriveexperiment-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.85 evidence: POST /hyperdrive/v1.0/{armScope}/runs — "Create An Experiment"; schemas HyperDriveExperiment, HyperDrivePolicyConfigBase, operationId microsoftAzureHyperparametertuningCreateexperiment reason: HyperDrive is Azure Machine Learning's hyperparameter-tuning service; creating and cancelling tuning runs is ML model lifecycle work, i.e. AI/ML management — not product A/B experimentation. - tag: InventoryItems spec_file: microsoft-azure-inventory-items-api-openapi.yml reanchored_from: microsoft-azure-inventoryitems-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: Microsoft.ConnectedVMwarevSphere/vcenters/{vcenterName}/inventoryItems and Microsoft.ScVmm/vmmServers/{vmmServerName}/inventoryItems; 'Implements Get For The List Of Inventory Items In The Vmmserver' reason: Despite the 'Inventory' homograph, these are virtualization inventory objects (VMs, hosts, networks) discovered from vCenter and SCVMM servers — IT infrastructure asset discovery, definitively not stock/supply-chain inventory. - tag: Model spec_file: microsoft-azure-model-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.85 evidence: POST .../MachineLearningServices/workspaces/{workspace}/models — "Register A Model"; GET .../models/{id}/metrics — "Retrieve The Metrics For A Model" reason: 'Machine learning model registry: register, query, patch, delete models and retrieve model metrics — this is ML model lifecycle / MLOps, i.e. Artificial Intelligence Management.' - tag: NetApp Accounts spec_file: microsoft-azure-netapp-accounts-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '''Describe All Netapp Accounts In A Subscription''; ''Migrate Volumes Encryption Key Source''; schema netAppAccount' reason: Manages Azure NetApp Files storage accounts — cloud storage infrastructure provisioning, not a business account capability. - tag: NetApp Resource spec_file: microsoft-azure-netapp-resource-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '''Check Quota Availability'', ''Get Quota Limits'', ''Describes Region Specific Information''' reason: Region/quota/network metadata operations for the NetApp storage service — cloud infrastructure management. - tag: Network Connections spec_file: microsoft-azure-network-connections-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: schemas NetworkConnection, NetworkProperties, DomainJoinType; 'networkConnections/{networkConnectionName}/healthChecks' reason: CRUD and health checks over DevCenter network connection resources — network infrastructure management. - tag: OutboundEndpoints spec_file: microsoft-azure-outboundendpoints-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: Microsoft.Network/dnsResolvers/{dnsResolverName}/outboundEndpoints ... OutboundEndpointProperties reason: CRUD over DNS resolver outbound endpoints — pure network infrastructure provisioning. - tag: PatchAccessReviewMyInstanceDecision spec_file: microsoft-azure-patchaccessreviewmyinstancedecision-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: PATCH /providers/Microsoft.Authorization/accessReviewScheduleDefinitions/{scheduleDefinitionId}/instances/{id}/decisions/{decisionId}; schemas AccessReviewDecision, AccessReviewDecisionIdentity reason: Recording a reviewer's decision in an Azure AD access review under Microsoft.Authorization is access certification/recertification, squarely Identity & Access Management. - tag: PublicIpAddresses spec_file: microsoft-azure-publicipaddresses-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: PUT/GET/DELETE .../providers/Microsoft.Network/publicIPAddresses/{publicIpAddressName}; schemas PublicIpAddressPropertiesFormat, PublicIpAddressDnsSettings reason: Full CRUD lifecycle over Azure Network public IP address resources — provisioning and managing cloud network infrastructure, which is IT Infrastructure Management. - tag: ResourceGroups spec_file: microsoft-azure-resource-groups-api-openapi.yml reanchored_from: microsoft-azure-resourcegroups-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '"Deletes A Resource Group", "Updates A Resource Group", PUT /subscriptions/{subscriptionId}/resourcegroups/{resourceGroupName}, schemas ResourceGroup, GenericResource, Sku' reason: CRUD over Azure Resource Manager resource groups and their contained resources — provisioning and organising cloud compute/storage infrastructure. Plainly IT infrastructure management. - tag: Resources spec_file: microsoft-azure-resources-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '"List All Resources in a Subscription", "Moves Resources From One Resource Group To Another Resource Group"' reason: Generic Azure Resource Manager CRUD, listing, move/validate-move and Resource Graph query over cloud resources — direct management of compute/storage/cloud infrastructure inventory. - tag: RouteTables spec_file: microsoft-azure-route-tables-api-openapi.yml reanchored_from: microsoft-azure-routetables-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: PUT /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Network/routeTables/{routeTableName}; schema RouteTablePropertiesFormat reason: CRUD over Microsoft.Network route tables — cloud network infrastructure provisioning, i.e. IT infrastructure management. - tag: Routes spec_file: microsoft-azure-routes-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: PUT .../Microsoft.Network/routeTables/{routeTableName}/routes/{routeName}; schemas RoutePropertiesFormat, RouteListResult reason: Individual network routes inside an Azure route table — network/cloud infrastructure configuration, not business routing. - tag: RoutingConfigurations spec_file: microsoft-azure-routingconfigurations-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: PUT .../Microsoft.Network/networkManagers/{networkManagerName}/routingConfigurations/{configurationName}; schema RoutingConfigurationPropertiesFormat reason: Azure Virtual Network Manager routing configuration resources — cloud network infrastructure management. - tag: ScaleUnitNodes spec_file: microsoft-azure-scaleunitnodes-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: 'scaleUnitNodes/{scaleUnitNode}/PowerOn ... /StartMaintenanceMode ... /Repair; schemas: BareMetalNodeDescription, ScaleUnitNode' reason: Power, maintenance-mode and repair operations on bare-metal fabric nodes — hands-on compute infrastructure administration. - tag: ServicePrincipalAppRoleAssignedTo spec_file: microsoft-azure-serviceprincipalapproleassignedto-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: '"Principals Users, Groups, And Service Principals That Are Assigned To This Service Principal"; schema AppRoleAssignment' reason: Lists app role assignments granted to users, groups and service principals — access-rights administration in the directory, i.e. Identity & Access Management. - tag: ServicePrincipalAppRoleAssignments spec_file: microsoft-azure-serviceprincipalapproleassignments-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: '"Applications That The Service Principal Is Assigned To"; schemas AppRoleAssignment, AppRoleAssignmentListResult' reason: Enumerates the application role assignments held by a service principal — directory authorisation data, Identity & Access Management. - tag: SqlVirtualMachines spec_file: microsoft-azure-sqlvirtualmachines-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: 'PUT .../Microsoft.SqlVirtualMachine/sqlVirtualMachines/{sqlVirtualMachineName} Createorupdate; POST .../redeploy; schemas: AutoPatchingSettings, AutoBackupSettings, StorageConfigurationSettings' reason: Full lifecycle of SQL Server virtual machine resources including storage configuration, auto-patching and redeploy — cloud compute infrastructure management. - tag: StandbyVirtualMachines spec_file: microsoft-azure-standbyvirtualmachines-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: GET .../providers/Microsoft.StandbyPool/standbyVirtualMachinePools/{standbyVirtualMachinePoolName}/standbyVirtualMachines — schemas StandbyVirtualMachineResource, ProvisioningState reason: Operations read virtual machine resources from a standby pool — cloud compute infrastructure provisioning/management, i.e. IT Infrastructure Management. - tag: StaticMembers spec_file: microsoft-azure-staticmembers-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: PUT .../Microsoft.Network/networkManagers/{networkManagerName}/networkGroups/{networkGroupName}/staticMembers/{staticMemberName} — schema StaticMemberProperties reason: CRUD over static members of Azure Network Manager network groups — network infrastructure configuration, i.e. IT Infrastructure Management. 'Members' here are network resources, not people. - tag: Storage spec_file: microsoft-azure-storage-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: Microsoft Azure Backs Up The Specified Storage Account; Microsoft Azure Restores A Backed Up Storage Account To A Vault; schemas StorageAccountCreateParameters, SasDefinitionBundle reason: Management of cloud storage accounts, keys and SAS definitions — storage infrastructure administration. - tag: StorageAccounts spec_file: microsoft-azure-storageaccounts-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: Microsoft Azure Creates A New Storageaccount Or Updates An Existing Storageaccount On The Device; Microsoft Azure Lists All The Storageaccounts In A Data Box Edge Data Box Gateway Device reason: CRUD over storage accounts and containers attached to Azure devices and Data Lake Analytics accounts — cloud storage infrastructure management. 'Accounts' here are storage resources, not customers. - tag: StorageClass spec_file: microsoft-azure-storageclass-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: PUT /{resourceUri}/providers/Microsoft.KubernetesRuntime/storageClasses/{storageClassName} — schemas StorageClassProperties, VolumeBindingMode, PerformanceTier reason: Manages Kubernetes storage classes and volume provisioning tiers — container storage infrastructure configuration. - tag: Subnets spec_file: microsoft-azure-subnets-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: PUT .../Microsoft.Network/virtualnetworks/{virtualNetworkName}/subnets/{subnetName}; schemas Subnet, SubnetPropertiesFormat reason: CRUD of virtual network subnets — cloud network infrastructure provisioning, squarely IT Infrastructure Management (compute, storage, network, cloud). - tag: User spec_file: microsoft-azure-user-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: 'POST /{tenantID}/users microsoftAzureUsersCreate ... DELETE /{tenantID}/users/{upnOrObjectId} ... schemas: PasswordProfile, UserGetMemberGroupsResult, DirectoryObject' reason: Full lifecycle CRUD over directory user objects in a tenant, with password profiles and group membership resolution — this is directory identity administration, i.e. Identity & Access Management. - tag: VirtualMachineInstances spec_file: microsoft-azure-virtualmachineinstances-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '''Implements The Operation To Stop A Virtual Machine'', ''Gets A Virtual Machine'' under Microsoft.ConnectedVMwarevSphere/virtualMachineInstances' reason: CRUD plus start/stop/restart of VMware-backed virtual machine instances, with StorageProfile/NetworkProfile schemas — clearly compute/infrastructure management. - tag: VirtualMachines spec_file: microsoft-azure-virtualmachines-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: Microsoft Azure Implements The Operation To Start A Virtual Machine; Microsoft Azure Implements Virtual Machine Put Method reason: Full lifecycle of virtual machines (create, start, stop, restart, patch) is cloud compute infrastructure management. - tag: VirtualNetworks spec_file: microsoft-azure-virtualnetworks-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: Microsoft Azure Implements Virtual Network Put Method; Microsoft Azure Gets A Virtual Network reason: CRUD over virtual networks and subnets is core cloud network infrastructure management. - tag: VmwareHostController spec_file: microsoft-azure-vmwarehostcontroller-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: GET .../Microsoft.OffAzure/vmwareSites/{siteName}/hosts; schemas VmwareHost, VmwareDatastore, VmwareHostProperties reason: Lists and reads discovered VMware hosts and datastores at an on-premises site — compute/storage infrastructure inventory. - tag: VolumeContainers spec_file: microsoft-azure-volumecontainers-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: /providers/Microsoft.StorSimple/managers/{managerName}/devices/{deviceName}/volumeContainers; schemas VolumeContainer, MetricDefinition reason: CRUD and metrics for StorSimple storage device volume containers — storage infrastructure provisioning and monitoring. - tag: Volumes spec_file: microsoft-azure-volumes-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: GET .../Microsoft.ContainerStorage/pools/{poolName}/volumes ... microsoftAzureVolumesCreateorupdate; schemas 'VolumeList', 'IscsiTargetInfo', 'mountTargetProperties' reason: CRUD over cloud storage volumes (ContainerStorage pools, ElasticSan, NetApp capacity pools) — provisioning of storage infrastructure, i.e. IT Infrastructure Management. - tag: VpnGateways spec_file: microsoft-azure-vpngateways-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: POST .../Microsoft.Network/vpnGateways/{gatewayName}/startpacketcapture; schemas 'VpnGatewayProperties', 'VpnSiteLinkConnection', 'StaticRoute' reason: Management of network VPN gateways, routing and packet capture — network infrastructure management. - tag: WorkloadNetworks spec_file: microsoft-azure-workloadnetworks-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '''Create A Segment By Id In A Private Cloud Workload Network'', ''Create Dhcp By Id In A Private Cloud Workload Network'', WorkloadNetworkGateway' reason: Network segments, DHCP configurations, gateways and DNS in Azure VMware private clouds — network infrastructure provisioning, squarely IT Infrastructure Management. - tag: VolumeQuotaRules spec_file: microsoft-azure-volumequotarules-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.83 evidence: '''Get All Quota Rules For A Volume'', ''Create A Quota Rule'' under Microsoft.NetApp/.../volumes/{volumeName}/volumeQuotaRules' reason: Storage quota rules on NetApp volumes — capacity control over cloud storage infrastructure, not a commercial entitlement or API-consumption quota. - tag: Agent Pools spec_file: microsoft-azure-agent-pools-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.82 evidence: 'openapi description: ''Operations for managing node pools within a cluster''; AgentPools_CreateOrUpdate ''Create or Update an Agent Pool''; schema ManagedClusterAgentPoolProfile' reason: Lifecycle management of Kubernetes node pools in Azure Container Service — compute infrastructure provisioning, squarely IT Infrastructure Management. - tag: ExpressRouteCircuitAuthorizations spec_file: microsoft-azure-expressroutecircuitauthorizations-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.82 evidence: PUT .../Microsoft.Network/expressRouteCircuits/{circuitName}/authorizations/{authorizationName}; schema ExpressRouteCircuitAuthorization reason: Manages authorization keys on ExpressRoute private network circuits — network infrastructure provisioning, not identity/access governance of people. - tag: ManagedHostingEnvironments spec_file: microsoft-azure-managedhostingenvironments-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.82 evidence: '"Create Or Update A Managed Hosting Environment"; "Get List Of Ip Addresses Assigned To A Managed Hosting Environment"; schema StampCapacity' reason: Lifecycle of App Service hosting environments, their capacities, VIPs and hosted server farms — cloud hosting infrastructure management. - tag: Networks spec_file: microsoft-azure-networks-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.82 evidence: '"Creates Or Updates A Network Resource", "Gets All The Network Resources In A Given Subscription"' reason: Create/read/delete of Service Fabric Mesh network resources — direct cloud network infrastructure provisioning. - tag: OAuth2PermissionGrant_Create spec_file: microsoft-azure-oauth2permissiongrant-create-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.82 evidence: POST /{tenantID}/oauth2PermissionGrants with schema OAuth2PermissionGrant reason: Creates OAuth2 delegated permission grants in the directory tenant — granting application access rights to identities, which is Identity & Access Management. - tag: OAuth2PermissionGrant_List spec_file: microsoft-azure-oauth2permissiongrant-list-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.82 evidence: GET /{tenantID}/oauth2PermissionGrants; schemas OAuth2PermissionGrant, OAuth2PermissionGrantListResult reason: Lists directory OAuth2 permission grants — inspection of access entitlements granted to applications, i.e. Identity & Access Management. - tag: OAuth2PermissionGrant_delete spec_file: microsoft-azure-oauth2permissiongrant-delete-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.82 evidence: DELETE /{tenantID}/oauth2PermissionGrants/{objectId} reason: Revokes an OAuth2 permission grant in the tenant directory — access revocation, part of Identity & Access Management. - tag: TenantLevelGetAccessReviewInstanceContactedReviewers spec_file: microsoft-azure-tenantlevelgetaccessreviewinstancecontactedreviewers-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.82 evidence: GET /providers/Microsoft.Authorization/accessReviewScheduleDefinitions/{scheduleDefinitionId}/instances/{id}/contactedReviewers — schemas AccessReviewContactedReviewer reason: Access review schedule definitions and reviewers under Microsoft.Authorization are access certification/recertification, a core Identity & Access Management activity. - tag: amlFilesystems spec_file: microsoft-azure-amlfilesystems-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.82 evidence: providers/Microsoft.StorageCache/amlFilesystems/{amlFilesystemName} ... AmlFilesystemHsmSettings, AmlFilesystemArchive, checkAmlFSSubnets reason: Lifecycle of Azure Managed Lustre (StorageCache) filesystems including archive and subnet sizing — cloud storage infrastructure provisioning. - tag: AzureLargeInstances spec_file: microsoft-azure-azurelargeinstances-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: azureLargeInstances/{name}/restart, /shutdown, /start; schemas HardwareProfile, StorageProfile, NetworkProfile, AzureLargeInstancePowerStateEnum reason: Lifecycle and power control of large bare-metal compute instances with hardware, storage and network profiles — unambiguously compute/cloud infrastructure management. - tag: AzureLargeStorageInstances spec_file: microsoft-azure-azurelargestorageinstances-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: GET/PATCH .../azureLargeStorageInstances/{azureLargeStorageInstanceName}; schemas StorageProperties, StorageBillingProperties reason: CRUD over large storage instance resources — storage infrastructure provisioning and stewardship, i.e. IT Infrastructure Management. - tag: Backup Policy spec_file: microsoft-azure-backup-policy-api-openapi.yml capability_id: BC-4220.60 capability_id_l1: BC-4220 capability_name: Disaster Recovery & Resilience confidence: 0.8 evidence: 'Microsoft Azure Create A Backup Policy ... schemas: backupPolicy, volumeBackups, backupPolicyProperties' reason: CRUD over NetApp backup policies defining backup schedules/retention for volumes — backup and restore stewardship, i.e. disaster recovery and resilience operations for a cloud service. - tag: Backup Restore spec_file: microsoft-azure-backup-restore-api-openapi.yml capability_id: BC-4220.60 capability_id_l1: BC-4220 capability_name: Disaster Recovery & Resilience confidence: 0.8 evidence: 'cloudEndpoints/{cloudEndpointName}/prebackup ... /postrestore; schemas: PostRestoreRequest, PreRestoreRequest, BackupRequest, RestoreFileSpec' reason: Operations orchestrate pre/post backup and restore of Storage Sync cloud endpoints — backup and restore capability. - tag: Backup Vaults spec_file: microsoft-azure-backup-vaults-api-openapi.yml capability_id: BC-4220.60 capability_id_l1: BC-4220 capability_name: Disaster Recovery & Resilience confidence: 0.8 evidence: 'Microsoft Azure Create Or Update A Backup Vault ... schemas: backupVault, backupVaultProperties' reason: Manages NetApp backup vaults that hold backup data; this is backup/restore infrastructure management, not a financial vault. - tag: BackupRestore spec_file: microsoft-azure-backup-restore-api-openapi.yml reanchored_from: microsoft-azure-backuprestore-api-openapi.yml capability_id: BC-160.20 capability_id_l1: BC-160 capability_name: Disaster Recovery Management confidence: 0.8 evidence: '"Creates A Backup Policy", "Enables Periodic Backup Of Stateful Partitions Under This Service Fabric Application", "Gets The List Of Backups Available For Every Partition"' reason: Operations create backup policies and enable/suspend/resume periodic backup and restore of Service Fabric applications — squarely backup-and-restore / IT disaster recovery. - tag: BgpPeers spec_file: microsoft-azure-bgppeers-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: PUT /{resourceUri}/providers/Microsoft.KubernetesRuntime/bgpPeers/{bgpPeerName} microsoftAzureBgppeersCreateorupdate; schemas BgpPeer, BgpPeerProperties reason: CRUD over BGP peering configuration for a Kubernetes runtime — network infrastructure configuration, i.e. IT infrastructure management. - tag: CloudServices spec_file: microsoft-azure-cloudservices-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: PUT /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Compute/cloudServices/{cloudServiceName} ... /start, /poweroff, /restart, /reimage; schema CloudServiceNetworkProfile reason: Lifecycle and power operations over Azure Compute cloud service resources — provisioning and running cloud compute infrastructure, i.e. IT Infrastructure Management. No business-domain capability is realised. - tag: Clouds spec_file: microsoft-azure-clouds-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: microsoftAzureCloudsGet 'Gets A Cloud' on /providers/Microsoft.ScVmm/clouds/{cloudName}; schemas CloudCapacity, StorageQoSPolicy, ExtendedLocation reason: CRUD over SCVMM private-cloud resources with capacity and storage QoS — management of virtualised compute/storage infrastructure. - tag: Clusters spec_file: microsoft-azure-clusters-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '''Implements Cluster Put Method'' on /providers/Microsoft.ConnectedVMwarevSphere/clusters/{clusterName} and /Microsoft.DBforPostgreSQL/serverGroupsv2/{clusterName}' reason: Lifecycle management of VMware vSphere and PostgreSQL clusters as Azure resources — compute/database infrastructure provisioning. - tag: Communications spec_file: microsoft-azure-communications-api-openapi.yml capability_id: BC-430.10 capability_id_l1: BC-430 capability_name: Customer Inquiry Management confidence: 0.8 evidence: GET /providers/Microsoft.Support/supportTickets/{supportTicketName}/communications; schema CommunicationDetails reason: Creates and reads communications (correspondence) on Azure Support tickets — support case correspondence handling, i.e. customer inquiry/support ticket management. - tag: Containers spec_file: microsoft-azure-containers-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '''Operations on blob containers''; ''Create a Container'', ''List Blobs in a Container'', ''Lists All The Containers Of A Storage Account In A Data Box Edge Data Box Gateway Device''' reason: Management of blob/storage containers and Cosmos collections — cloud storage infrastructure administration, i.e. IT Infrastructure Management. Not a business-domain container. - tag: DedicatedCloudServices spec_file: microsoft-azure-dedicatedcloudservices-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"Implements Dedicated Cloud Service Put Method" under Microsoft.VMwareCloudSimple/dedicatedCloudServices' reason: CRUD over dedicated cloud service resources (private cloud footprint) — cloud infrastructure provisioning and management. - tag: DeleteAccessReviewScheduleDefinition spec_file: microsoft-azure-deleteaccessreviewscheduledefinition-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: DELETE /subscriptions/{subscriptionId}/providers/Microsoft.Authorization/accessReviewScheduleDefinitions/{scheduleDefinitionId} reason: Access review schedule definitions under Microsoft.Authorization are periodic entitlement recertification objects, squarely identity and access management rather than any business review process. - tag: DiskPools spec_file: microsoft-azure-diskpools-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: APIs for Disk pool operations. ... POST .../diskPools/{diskPoolName}/deallocate microsoftAzureDiskpoolsDeallocate reason: Create, update, start and deallocate storage disk pools (DiskPoolCreate, DiskPoolProperties) — provisioning and operating cloud storage infrastructure. - tag: Disks spec_file: microsoft-azure-disks-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: 'POST .../labs/{labName}/users/{userName}/disks/{name}/attach microsoftAzureDisksAttach; schemas: DiskProperties, AttachDiskProperties, DetachDiskProperties' reason: Lifecycle of virtual disks including attach/detach to compute — management of cloud storage/compute infrastructure resources. - tag: ExpressRouteCrossConnectionPeerings spec_file: microsoft-azure-expressroutecrossconnectionpeerings-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: 'schemas: ExpressRouteCrossConnectionPeeringProperties, ExpressRouteCrossConnectionPeering; PUT .../expressRouteCrossConnections/{crossConnectionName}/peerings/{peeringName}' reason: CRUD over BGP peerings on ExpressRoute cross-connections — provisioning of cloud network connectivity, i.e. IT infrastructure (network) management. - tag: ExpressRouteCrossConnections spec_file: microsoft-azure-expressroutecrossconnections-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: 'schemas: ExpressRouteCrossConnection, ExpressRouteCircuitReference; microsoftAzureExpressroutecrossconnectionsCreateorupdate' reason: Lifecycle management of dedicated private network circuits into Azure — clearly network/cloud infrastructure provisioning, not a business-domain capability. - tag: ExpressRouteGateways spec_file: microsoft-azure-expressroutegateways-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: 'schemas: ExpressRouteGatewayProperties, RoutingConfiguration, StaticRoute, PropagatedRouteTable; microsoftAzureExpressroutegatewaysCreateorupdate' reason: Create/update/delete of ExpressRoute gateways and their routing configuration is cloud network infrastructure management. - tag: 'Fine-Tunes:' spec_file: microsoft-azure-fine-tunes-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.8 evidence: 'Microsoft Azure Creates A Job That Fine Tunes A Specified Model From A Given Training File; schemas: FineTune, HyperParameters, FileStatistics' reason: Operations create, monitor, cancel and delete model fine-tuning jobs with training/validation files and hyperparameters — machine-learning model lifecycle (MLOps) management. - tag: 'Fine-Tuning:' spec_file: microsoft-azure-fine-tuning-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.8 evidence: 'POST /fine_tuning/jobs — Creates A Job That Fine Tunes A Specified Model From A Given Training File; schemas: FineTuningJob, FineTuningHyperParameters, FineTuningState' reason: Fine-tuning job lifecycle for Azure OpenAI models (create, list, get, events, cancel, delete) — AI/ML model lifecycle and MLOps management. - tag: FrontDoors spec_file: microsoft-azure-frontdoors-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: Microsoft.Network/frontDoors ... frontendEndpoints ... schemas LoadBalancingSettingsProperties, BackendPool, HealthProbeSettingsProperties, CacheConfiguration reason: Azure Front Door is cloud network/CDN edge infrastructure provisioning (load balancing, routing rules, HTTPS certificates) — IT Infrastructure Management. - tag: GlobalRulestack spec_file: microsoft-azure-globalrulestack-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.8 evidence: paths under /providers/PaloAltoNetworks.Cloudngfw/globalRulestacks with "Listfirewalls", "Listadvancedsecurityobjects", "Listpredefinedurlcategories"; schemas securityServices, PredefinedUrlCategory, RulestackProperties reason: Palo Alto Cloud NGFW global rulestacks are firewall rule/security-policy configuration objects — network security control management. Clearly cybersecurity, but the evidence does not pin one sub-capability (security architecture vs. threat detection), so only the L1 is asserted. - tag: Glossary spec_file: microsoft-azure-glossary-api-openapi.yml capability_id: BC-610.10 capability_id_l1: BC-610 capability_name: Data Governance Management confidence: 0.8 evidence: GET /atlas/v2/glossary ListGlossaries; "Create Glossary Term"; schemas AtlasGlossaryTerm, AtlasGlossaryCategory, AtlasClassification, TermCustomAttributes reason: Apache Atlas glossary APIs in Purview manage business glossary terms, categories and classifications over catalogued data assets — the stewardship/taxonomy core of data governance. Some overlap with knowledge/business-information modelling, hence 0.8 rather than higher. - tag: HostingEnvironments spec_file: microsoft-azure-hostingenvironments-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"Create Or Update A Hostingenvironment App Service Environment"; "Get Used, Available, And Total Worker Capacity For Hostingenvironment"; "Reboots All Machines In A Hostingenvironment"' reason: Manages App Service Environments — dedicated compute/network hosting infrastructure including capacity, VIPs, reboot and diagnostics. This is cloud infrastructure management. - tag: IscsiTargets spec_file: microsoft-azure-iscsitargets-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: APIs for iSCSI target operations ... providers/Microsoft.StoragePool/diskPools/{diskPoolName}/iscsiTargets reason: Create/update/delete of iSCSI targets within Azure disk pools, with ACL and LUN schemas — provisioning of block storage infrastructure, IT Infrastructure Management. - tag: MachinesController spec_file: microsoft-azure-machinescontroller-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: paths ".../Microsoft.OffAzure/vmwareSites/{siteName}/machines/{machineName}/start" and "/stop"; schema VmwareMachineProperties reason: Lists, updates, starts and stops discovered VMware virtual machines — direct management of compute infrastructure resources. - tag: ManagedNetworks spec_file: microsoft-azure-managednetworks-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: providers/Microsoft.ManagedNetwork/managedNetworks — schemas ManagedNetworkPeeringPolicy, ConnectivityCollection reason: Operations create/update/delete Azure managed network resources and peering policies — cloud network infrastructure provisioning, i.e. IT Infrastructure Management. No business-domain reading fits. - tag: ManagedPrivateEndpoints spec_file: microsoft-azure-managedprivateendpoints-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: PUT /managedVirtualNetworks/{managedVirtualNetworkName}/managedPrivateEndpoints/{managedPrivateEndpointName} reason: Lifecycle of private network endpoints inside managed virtual networks — pure cloud network infrastructure configuration. - tag: ManagedVirtualNetworks spec_file: microsoft-azure-managedvirtualnetworks-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: GET /managedvirtualnetworks/{managedVirtualNetworkName}, schema ManagedVirtualNetworkProperties reason: Create, list and delete managed virtual networks and their private endpoints — cloud network infrastructure management. - tag: Managers spec_file: microsoft-azure-managers-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: providers/Microsoft.StorSimple/managers/{managerName}/devices/{deviceName}/publicEncryptionKey — schemas Manager, ManagerSku, EncryptionSettings reason: 'StorSimple storage device manager resources: create/update managers, device encryption keys, extended vault info. Storage infrastructure management, not people management despite the tag string.' - tag: Multivariate spec_file: microsoft-azure-multivariate-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.8 evidence: '"Train A Multivariate Anomaly Detection Model"; "List Multivariate Models"; schema "Multivariate.AnomalyDetectionModel"' reason: 'Model training, listing, deletion and inference for anomaly detection — plainly AI/ML model lifecycle management. Note: anomaly detection here is generic time-series ML, not financial-crime detection.' - tag: NetworkFunctions spec_file: microsoft-azure-networkfunctions-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: schemas NetworkFunctionResource, NetworkFunctionOperationalStatus; 'Microsoft.MobilePacketCore/networkFunctions' reason: Provisioning of mobile packet core network function resources — cloud/network infrastructure management. - tag: NetworkGroups spec_file: microsoft-azure-networkgroups-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '''networkManagers/{networkManagerName}/networkGroups''; schema EffectiveVirtualNetworksListResult' reason: Azure Network Manager network group CRUD and effective virtual network listing — network infrastructure management. - tag: NetworkManagers spec_file: microsoft-azure-networkmanagers-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: PUT .../Microsoft.Network/networkManagers/{networkManagerName} (Createorupdate), POST .../commit, POST .../listDeploymentStatus reason: Full CRUD and deployment of Azure Network Manager resources — provisioning and operating cloud network infrastructure. - tag: OutboundNetworkDependenciesEndpoints spec_file: microsoft-azure-outboundnetworkdependenciesendpoints-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: Gets A List Of Egress Endpoints Network Endpoints Of All Outbound Dependencies In The Specified Workspace reason: Lists network egress/FQDN dependencies for workspaces — network infrastructure configuration information. - tag: Partition spec_file: microsoft-azure-partition-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.8 evidence: Gets The Health Of The Specified Service Fabric Partition; Indicates To The Service Fabric Cluster That It Should Attempt To Recover A Specific Partition That Is Currently Stuck In Quorum Loss reason: Service Fabric partition health, load and recovery operations — day-to-day platform operations and monitoring of running infrastructure. - tag: Pool spec_file: microsoft-azure-pool-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: POST .../batchAccounts/{accountName}/pools/{poolName}/stopResize — 'Stops An Ongoing Resize Operation On The Pool'; schemas VirtualMachineConfiguration, AutoScaleSettings, ComputeNodeDeallocationOption reason: Azure Batch compute pool resources — provisioning and scaling of compute infrastructure, i.e. IT infrastructure (compute/cloud) management, not any business-domain 'pool'. - tag: Pools spec_file: microsoft-azure-pools-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '''Creates A Pool To The Specified Account'', ''Enables Automatic Scaling For A Pool'', ''Lists The Compute Nodes In The Specified Pool''' reason: Batch service pool and compute node lifecycle/autoscaling — cloud compute infrastructure management. - tag: PrivateClouds spec_file: microsoft-azure-privateclouds-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: PUT ... /Microsoft.AVS/privateClouds/{privateCloudName} — Create Or Update A Private Cloud; Rotate The Nsx T Manager Password; List The Admin Credentials For The Private Cloud reason: Lifecycle management of Azure VMware Solution private cloud estates (create/update/delete, credential rotation, cluster/resource pool schemas) — provisioning and operating compute/network infrastructure, i.e. IT Infrastructure Management. - tag: PrivateEndpointConnections spec_file: microsoft-azure-private-endpoint-connections-api-openapi.yml reanchored_from: microsoft-azure-privateendpointconnections-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: GET ".../Microsoft.AppConfiguration/configurationStores/{configStoreName}/privateEndpointConnections" and 72 similar operations across providers reason: Broad set of private endpoint connection CRUD operations across many Azure resource providers; this is private network access configuration for cloud resources — IT Infrastructure Management. - tag: PrivateLink spec_file: microsoft-azure-private-link-api-openapi.yml reanchored_from: microsoft-azure-privatelink-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"Approves Or Rejects Private Endpoint Connection this Is A Public Api That Can Be Called Directly By Notification Hubs Users"; schemas "PrivateLinkResource", "PrivateLinkConnectionStatus"' reason: Private Link resources and endpoint connection approval across Azure services — private network connectivity for cloud infrastructure, i.e. IT Infrastructure Management. - tag: PrivateZones spec_file: microsoft-azure-privatezones-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: 'PUT/PATCH/DELETE/GET .../Microsoft.Network/privateDnsZones/{privateZoneName}; schemas: PrivateZone, PrivateZoneProperties' reason: Full lifecycle management of Azure Private DNS zones under Microsoft.Network — network infrastructure provisioning, squarely IT Infrastructure Management. - tag: ProjectApi spec_file: microsoft-azure-project-api-api-openapi.yml reanchored_from: microsoft-azure-projectapi-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.8 evidence: 'schemas: TrainingParameters, Iteration, IterationPerformance, Prediction, ImageTag, CustomVisionError; ''Get Iterations For The Project''' reason: Custom Vision training projects — training iterations, tagged images, model performance and prediction export. This is ML model lifecycle management (train, evaluate, version, export), mapping to Artificial Intelligence Management rather than any project-portfolio capability. - tag: PutAccessReviewDefaultSettings spec_file: microsoft-azure-putaccessreviewdefaultsettings-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: PUT .../Microsoft.Authorization/accessReviewScheduleSettings/default, schemas AccessReviewDefaultSettings, AccessReviewRecurrenceSettings reason: Configures recurring access review settings under Microsoft.Authorization — access certification/review, part of Identity & Access Management. - tag: PutAccessReviewHistoryDefinition spec_file: microsoft-azure-putaccessreviewhistorydefinition-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: PUT .../accessReviewHistoryDefinitions/{historyDefinitionId}, schemas AccessReviewHistoryDefinition, AccessReviewScope reason: Creates access review history definitions for reporting on access certifications — Identity & Access Management (access review/recertification). - tag: PutAccessReviewInstance spec_file: microsoft-azure-putaccessreviewinstance-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: PUT .../accessReviewScheduleDefinitions/{scheduleDefinitionId}/instances/{id}, schemas AccessReviewReviewer, AccessReviewInstance reason: Creates instances of access reviews with assigned reviewers — access certification within Identity & Access Management. - tag: PutAccessReviewScheduleDefinition spec_file: microsoft-azure-putaccessreviewscheduledefinition-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: PUT .../Microsoft.Authorization/accessReviewScheduleDefinitions/{scheduleDefinitionId}, schemas AccessReviewScheduleDefinition, AccessReviewReviewer reason: Defines scheduled access reviews with scope and reviewers — access recertification, an Identity & Access Management function. - tag: RecordSets spec_file: microsoft-azure-recordsets-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: PUT .../Microsoft.Network/dnsZones/{zoneName}/{recordType}/{relativeRecordSetName}; schemas ARecord, MxRecord_2, SrvRecord, TxtRecord reason: CRUD over DNS and private DNS zone record sets — network infrastructure configuration, squarely IT Infrastructure Management. - tag: ResourcePools spec_file: microsoft-azure-resource-pools-api-openapi.yml reanchored_from: microsoft-azure-resourcepools-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"Implements Resourcepool Put Method", "Gets A Resourcepool", paths under Microsoft.ConnectedVMwarevSphere/resourcePools and Microsoft.VMwareCloudSimple/.../privateClouds/{pcName}/resourcePools' reason: CRUD over VMware vSphere / private-cloud resource pools (aggregated compute capacity) — clearly compute infrastructure provisioning and management. - tag: RoleAssignments spec_file: microsoft-azure-role-assignments-api-openapi.yml reanchored_from: microsoft-azure-roleassignments-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: PUT .../hubs/{hubName}/roleAssignments/{assignmentName}; schemas RoleAssignment, AssignmentPrincipal reason: Create, read and delete role assignments binding principals to roles on a Customer Insights hub — access rights administration, i.e. identity and access management. - tag: Run spec_file: microsoft-azure-run-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.8 evidence: GET .../Microsoft.MachineLearningServices/workspaces/{workspaceName}/experiments/{experimentName}/runs/{runId} 'Get Run Details'; schemas Run, CreateRun, PaginatedRunList reason: Azure Machine Learning experiment run history — ML experiment tracking, part of AI/ML model lifecycle (MLOps). - tag: SerialPorts spec_file: microsoft-azure-serialports-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: providers/Microsoft.SerialConsole/serialPorts/{serialPort}/connect — microsoftAzureSerialportsConnect reason: Serial Console ports on Azure compute resources are infrastructure-level access to VMs; CRUD plus connect on Microsoft.SerialConsole is IT infrastructure management. - tag: ServerEndpoint Resource spec_file: microsoft-azure-serverendpoint-resource-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: PUT .../Microsoft.StorageSync/storageSyncServices/.../serverEndpoints/{serverEndpointName}; schemas ServerEndpointCloudTieringStatus, ServerEndpointSyncStatus reason: Azure File Sync server endpoints with cloud tiering and sync status are storage infrastructure resources; managing them is IT infrastructure management. - tag: ServerFarms spec_file: microsoft-azure-serverfarms-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"Creates Or Updates An App Service Plan"; "Gets List Of Vnets Associated With App Service Plan"' reason: App Service Plans (serverfarms) provision compute capacity and network routes for hosted apps — clearly compute/network infrastructure management. - tag: Servers spec_file: microsoft-azure-servers-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"Providers Microsoft Analysisservices Servers Servername" with Create/Delete/Update/Suspend/Resume; schemas AnalysisServicesServerProperties, ClusterServerProperties' reason: Provisions, scales, suspends and deletes managed server resources (Analysis Services, PostgreSQL cluster servers) — cloud compute/database infrastructure provisioning and lifecycle. - tag: ServicePrincipalOwners spec_file: microsoft-azure-serviceprincipalowners-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: '"Directory Objects That Are Owners Of This Service Principal"; POST /{tenantID}/servicePrincipals/{objectId}/$links/owners microsoftAzureServiceprincipalsAddowner' reason: Manages ownership links on a directory service principal — administration of identity objects and who may administer them, Identity & Access Management. - tag: SqlVirtualMachineGroups spec_file: microsoft-azure-sqlvirtualmachinegroups-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: 'PUT .../Microsoft.SqlVirtualMachine/sqlVirtualMachineGroups/{sqlVirtualMachineGroupName} microsoftAzureSqlvirtualmachinegroupsCreateorupdate; schemas: WsfcDomainProfile' reason: CRUD over SQL VM availability groups (Windows failover cluster domain profile) — provisioning and management of compute/cluster infrastructure. - tag: StorageDomains spec_file: microsoft-azure-storagedomains-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: PUT .../Microsoft.StorSimple/managers/{managerName}/storageDomains/{storageDomainName} — schema StorageDomainProperties reason: CRUD over StorSimple storage domains (hybrid storage appliance configuration) — IT storage infrastructure management. - tag: StorageMovers spec_file: microsoft-azure-storagemovers-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: PUT .../providers/Microsoft.StorageMover/storageMovers/{storageMoverName} — schemas StorageMoverProperties, StorageMoverList reason: Lifecycle management of Azure Storage Mover resources used to migrate data into cloud storage — storage infrastructure management. - tag: VCenters spec_file: microsoft-azure-vcenters-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"Implements Vcenter Put Method", "Implements Get Vcenters In A Subscription", schemas VCenterProperties, VICredential' reason: Manages VMware vCenter resources connected to Azure — virtualisation/compute infrastructure lifecycle, squarely IT Infrastructure Management. - tag: VMExtensions spec_file: microsoft-azure-vmextensions-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"Create A Virtual Machine Extension Image", "Returns A List Of All Virtual Machine Extension Images"' reason: Administration of VM extension images in Azure Stack compute admin — compute infrastructure artefact management. - tag: VirtualMachine spec_file: microsoft-azure-virtual-machine-api-openapi.yml reanchored_from: microsoft-azure-virtualmachine-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '''Start A Lab Virtual Machine'', ''Stop A Lab Virtual Machine'', ''Re Image A Lab Virtual Machine''' reason: Lifecycle and power operations over compute VMs in Lab Services — management of compute infrastructure. - tag: VirtualNetworkGatewayConnections spec_file: microsoft-azure-virtualnetworkgatewayconnections-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: schemas VirtualNetworkGatewayConnection, ConnectionSharedKey, LocalNetworkGatewayPropertiesFormat reason: VPN/gateway connection provisioning is network infrastructure management within the cloud platform. - tag: VirtualNetworkGateways spec_file: microsoft-azure-virtualnetworkgateways-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: PUT .../Microsoft.Network/virtualnetworkgateways/{virtualNetworkGatewayName}; schema VirtualNetworkGatewayPropertiesFormat reason: Creating, resetting and deleting virtual network gateways is cloud network infrastructure management. - tag: VpnServerConfigurations spec_file: microsoft-azure-vpnserverconfigurations-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: PATCH .../Microsoft.Network/vpnServerConfigurations/{vpnServerConfigurationName}; schemas 'VpnServerConfigurationProperties', 'VpnServerConfigVpnClientRootCertificate' reason: Configuration of point-to-site VPN server settings and certificates — network infrastructure configuration, not a business capability. - tag: VpnSites spec_file: microsoft-azure-vpnsites-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: PATCH .../Microsoft.Network/vpnSites/{vpnSiteName}; schemas 'VpnSiteProperties', 'VpnLinkBgpSettings', 'DeviceProperties' reason: Represents branch VPN site network objects with BGP/link settings — network infrastructure management. - tag: customLocations spec_file: microsoft-azure-customlocations-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"Creates Or Updates A Custom Location", "Gets The List Of Enabled Resource Types", schema customLocationProperties' reason: Azure ExtendedLocation resource CRUD for placing workloads on infrastructure targets — IT infrastructure (cloud resource) management. - tag: documentClassifiers:build spec_file: microsoft-azure-document-classifiers-build-api-openapi.yml reanchored_from: microsoft-azure-documentclassifiers-build-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.8 evidence: POST /documentClassifiers:build BuildClassifier; schema BuildDocumentClassifierRequest, ClassifierDocumentTypeDetails reason: Trains/builds a document classifier model from labelled blob content — clearly AI/ML model creation and lifecycle management. - tag: documentModels:build spec_file: microsoft-azure-document-models-build-api-openapi.yml reanchored_from: microsoft-azure-documentmodels-build-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.8 evidence: POST /documentModels:build BuildModel; schemas BuildDocumentModelRequest, DocumentBuildMode reason: Trains a custom document model from training data in blob storage — AI/ML model training and lifecycle management. - tag: vNetPeering spec_file: microsoft-azure-vnetpeering-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: 'PUT .../Microsoft.Databricks/workspaces/{workspaceName}/virtualNetworkPeerings/{peeringName}; schemas: VirtualNetworkPeering, AddressSpace' reason: CRUD over virtual network peerings and address spaces is cloud network infrastructure provisioning, squarely IT Infrastructure Management. - tag: ApplicationKeyCredentials spec_file: microsoft-azure-applicationkeycredentials-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.78 evidence: GET /{tenantID}/applications/{applicationObjectId}/keyCredentials; schemas KeyCredential, KeyCredentialsUpdateParameters, GraphError reason: Azure AD Graph management of certificate/key credentials for directory application (service principal) identities — identity and access credential administration. - tag: ApplicationPasswordCredentials spec_file: microsoft-azure-applicationpasswordcredentials-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.78 evidence: GET /{tenantID}/applications/{applicationObjectId}/passwordCredentials; schemas PasswordCredential, PasswordCredentialsUpdateParameters reason: Listing and updating client secrets for Azure AD application identities — credential/secret administration within identity and access management. - tag: Atlas spec_file: microsoft-azure-atlas-api-openapi.yml capability_id: BC-610.10 capability_id_l1: BC-610 capability_name: Data Governance Management confidence: 0.78 evidence: POST /atlas/v2/entity/businessmetadata/import; schemas AtlasGlossaryTerm, AtlasClassification, AtlasEntityDef, AtlasTermAssignmentStatus reason: 'Purview/Atlas metadata catalogue: data entities, classifications, business metadata and glossary terms. This is data governance and cataloguing (stewardship, taxonomy, classification of data assets).' - tag: Budgets spec_file: microsoft-azure-budgets-api-openapi.yml capability_id: BC-600.80 capability_id_l1: BC-600 capability_name: IT Financial Management confidence: 0.78 evidence: GET /{scope}/providers/Microsoft.Consumption/budgets with schemas Budget, CurrentSpend, BudgetTimePeriod, Notification reason: Creates and manages consumption budgets with current-spend tracking and threshold notifications over Azure cloud spend — IT spend control and cost optimisation. Not corporate budgeting (BC-230.10) since the scope is cloud consumption cost. - tag: DeleteAccessReviewHistoryDefinition spec_file: microsoft-azure-deleteaccessreviewhistorydefinition-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.78 evidence: DELETE /subscriptions/{subscriptionId}/providers/Microsoft.Authorization/accessReviewHistoryDefinitions/{historyDefinitionId} reason: Operates on Microsoft.Authorization access review history definitions — access review/recertification artefacts, which is identity and access management. Single delete operation keeps confidence below 0.9. - tag: Deployments spec_file: microsoft-azure-deployments-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.78 evidence: 'openapi description: ''Operations for managing model deployments''; ''List Model Deployments'', ''Create or Update a Model Deployment'', POST /deployments/{deploymentId}/chat/completions, /embeddings' reason: Cognitive Services / Azure OpenAI model deployment lifecycle plus inference endpoints — AI/ML model lifecycle management. - tag: Execution spec_file: microsoft-azure-execution-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.78 evidence: POST .../Microsoft.MachineLearningServices/workspaces/{workspaceName}/experiments/{experimentName}/startrun — "Start A Run On A Remote Compute Target"; schemas RunConfiguration, TensorflowConfiguration reason: Azure Machine Learning run execution (start/cancel training runs on compute targets) is ML model lifecycle / MLOps tooling, which sits under Artificial Intelligence Management. - tag: FrontendsInterface spec_file: microsoft-azure-frontendsinterface-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: Microsoft.ServiceNetworking/trafficControllers/{trafficControllerName}/frontends ... schemas FrontendProperties, FrontendListResult reason: CRUD over networking frontends on an Azure traffic controller (Application Gateway for Containers) — cloud network infrastructure management. - tag: Group spec_file: microsoft-azure-group-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.78 evidence: microsoftAzureGroupsAddmember 'Post Tenantid Groups Groupobjectid $links Members'; schemas ADGroup, CheckGroupMembershipResult, GroupCreateParameters reason: Dominant surface is Azure AD/Graph directory group lifecycle and membership (create group, add/remove member, isMemberOf, list members), which is directory group and access administration — Identity & Access Management. Some operations are API Management workspace groups, which are also access-control constructs. - tag: IscsiDisks spec_file: microsoft-azure-iscsidisks-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: 'providers/Microsoft.StorSimple/managers/{managerName}/devices/{deviceName}/iscsiservers/{iscsiServerName}/disks ... schemas: ISCSIDisk, ISCSIDiskProperties, MetricDefinition' reason: CRUD and metrics over iSCSI disks on StorSimple storage devices — management of storage infrastructure, squarely IT Infrastructure Management. - tag: IscsiServers spec_file: microsoft-azure-iscsiservers-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: 'schemas: ISCSIServer, ISCSIServerProperties ... /iscsiservers/{iscsiServerName}/backup microsoftAzureIscsiserversBackupnow' reason: Management of iSCSI storage servers on StorSimple devices including backup trigger and metrics — storage infrastructure management (BC-600.50). - tag: Machines spec_file: microsoft-azure-machines-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: '"Gets A List Of Machines In The Migrate Project"; schemas VirtualMachineConfiguration, HypervisorConfiguration, OperatingSystemConfiguration' reason: Operations enumerate server/VM inventory, connections, processes and ports across migrate projects and Service Map — compute infrastructure discovery and inventory, i.e. IT Infrastructure Management. - tag: MeshNetworks spec_file: microsoft-azure-meshnetworks-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: '"Creates Or Updates A Network Resource", schemas NetworkResourceDescription, NetworkKind' reason: CRUD over network resources in Azure's mesh platform is provisioning of cloud network infrastructure, mapping to IT Infrastructure Management. - tag: MeshVolumes spec_file: microsoft-azure-meshvolumes-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: '"Creates Or Updates A Volume Resource", schemas VolumeProviderParametersAzureFile' reason: Provisioning of storage volumes backed by Azure Files is cloud storage infrastructure management. - tag: MongoClusters spec_file: microsoft-azure-mongoclusters-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: PUT/GET/DELETE/PATCH ".../Microsoft.DocumentDB/mongoClusters/{mongoClusterName}"; schemas MongoClusterProperties, NodeGroupSpec, MongoClusterRestoreParameters reason: CRUD provisioning of managed MongoDB clusters as Azure resources — cloud/database infrastructure management. - tag: PostAccessReviewHistoryDefinitionInstance spec_file: microsoft-azure-postaccessreviewhistorydefinitioninstance-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.78 evidence: POST /subscriptions/{subscriptionId}/providers/Microsoft.Authorization/accessReviewHistoryDefinitions/{historyDefinitionId}/instances/{instanceId}/generateDownloadUri; schema AccessReviewHistoryInstance reason: Access review history reporting under Microsoft.Authorization — part of identity and access governance/recertification. - tag: PrivateEndpointConnection spec_file: microsoft-azure-private-endpoint-connection-api-openapi.yml reanchored_from: microsoft-azure-privateendpointconnection-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: '"Microsoft Azure Approves Rejects Private Endpoint Connection Request"; schemas PrivateEndpoint, PrivateLinkServiceConnectionState' reason: Operations create, approve/reject, list and delete Azure Private Endpoint connections on cloud resources — private network connectivity configuration for cloud infrastructure, i.e. IT Infrastructure Management (compute, storage, network, cloud). No business-domain capability is realised. - tag: PrivateEndpointConnectionController spec_file: microsoft-azure-privateendpointconnectioncontroller-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: '"Microsoft Azure Create Or Update Private Endpoint"; "Get The Private Endpoint Connections"' reason: CRUD over private endpoint connections on Azure Migrate/OffAzure sites — cloud network connectivity plumbing, mapped to IT Infrastructure Management rather than any business capability. - tag: RootCauseAnalysisModel spec_file: microsoft-azure-rootcauseanalysismodel-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.78 evidence: '''Create A Training Model For Root Cause Analysis''; ''Create An Inference Task For Root Cause Analysis''; schema RootCauseAnalysisTrainingRequest' reason: Model training and inference task lifecycle for an AI service — squarely AI/ML model lifecycle (MLOps) management. - tag: ServicePrincipalKeyCredentials spec_file: microsoft-azure-serviceprincipalkeycredentials-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.78 evidence: PATCH /{tenantID}/servicePrincipals/{objectId}/keyCredentials microsoftAzureServiceprincipalsUpdatekeycredentials; schema KeyCredentialsUpdateParameters reason: Lists and updates certificate/key credentials attached to a service principal — lifecycle of machine identity credentials, part of Identity & Access Management (a secrets-management reading is possible, hence not maximal confidence). - tag: ServicePrincipalPasswordCredentials spec_file: microsoft-azure-serviceprincipalpasswordcredentials-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.78 evidence: PATCH /{tenantID}/servicePrincipals/{objectId}/passwordCredentials; schemas PasswordCredential, PasswordCredentialsUpdateParameters reason: Lists and updates client secrets for a service principal — machine identity credential administration within IAM. Not human password self-service, but still access-credential management. - tag: SessionHost spec_file: microsoft-azure-sessionhost-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: paths under "providers/Microsoft.DesktopVirtualization/hostPools/{hostPoolName}/sessionHosts" with schemas SessionHostHealthCheckReport, SessionHostProperties reason: CRUD and provisioning-retry over Azure Virtual Desktop session hosts (virtual machines in host pools) — management of compute infrastructure. - tag: Subvolumes spec_file: microsoft-azure-subvolumes-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: GET .../Microsoft.NetApp/netAppAccounts/{accountName}/capacityPools/{poolName}/volumes/{volumeName}/subvolumes List Of All The Subvolumes reason: CRUD over Azure NetApp Files subvolumes — provisioning and management of cloud storage objects, i.e. IT infrastructure (storage) management. - tag: SynapseRoleDefinitions spec_file: microsoft-azure-synapseroledefinitions-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.78 evidence: 'schemas: SynapseRbacPermission, RoleDefinitionsListResponse, SynapseRoleDefinition' reason: Operations list and retrieve RBAC role definitions and their permissions, i.e. the authorization model of the platform. Maps to Identity & Access Management (RBAC/entitlement administration). - tag: PrivateLinkResource spec_file: microsoft-azure-privatelinkresource-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.76 evidence: '"Gets A List Of Privately Linkable Resources For An Account"' reason: Read-only discovery of privately linkable cloud resources / link groups — cloud networking metadata, mapped to IT Infrastructure Management. - tag: AccessReviewInstanceAcceptRecommmendations spec_file: microsoft-azure-accessreviewinstanceacceptrecommmendations-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: POST /providers/Microsoft.Authorization/accessReviewScheduleDefinitions/{scheduleDefinitionId}/instances/{id}/acceptRecommendations reason: Azure AD/Authorization access review instances are entitlement recertification workflows; accepting reviewer recommendations is an identity governance action under IAM. - tag: AccessReviewInstanceApplyDecisions spec_file: microsoft-azure-accessreviewinstanceapplydecisions-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: POST /subscriptions/{subscriptionId}/providers/Microsoft.Authorization/accessReviewScheduleDefinitions/{scheduleDefinitionId}/instances/{id}/applyDecisions reason: Applying access review decisions revokes or confirms access grants — identity governance and access certification, part of Identity & Access Management. - tag: AggregatedCost spec_file: microsoft-azure-aggregatedcost-api-openapi.yml capability_id: BC-600.80 capability_id_l1: BC-600 capability_name: IT Financial Management confidence: 0.75 evidence: GET /providers/Microsoft.Management/managementGroups/{managementGroupId}/providers/Microsoft.Consumption/aggregatedcost; schema ManagementGroupAggregatedCostResult, billingPeriods/{billingPeriodName} reason: Retrieves aggregated cloud consumption cost per management group and billing period — cloud spend visibility and chargeback, i.e. IT Financial Management. Not general ledger or AP accounting. - tag: ContainerApps spec_file: microsoft-azure-container-apps-api-openapi.yml reanchored_from: microsoft-azure-containerapps-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: '''Create Or Update A Container App'', ''Get The Container Apps In A Given Subscription'', ''List Secrets For A Container App''' reason: Control-plane management of container application hosting resources (compute/cloud infrastructure provisioning), which realises IT Infrastructure Management for whoever consumes it. - tag: 'Custom Speech Model Evaluations:' spec_file: microsoft-azure-custom-speech-model-evaluations-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.75 evidence: POST /evaluations "Creates A New Evaluation"; schemas Evaluation, EvaluationProperties reason: Evaluation runs comparing speech model outputs are a core MLOps/model-lifecycle activity. - tag: Datastores spec_file: microsoft-azure-datastores-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: '"Gets A Datastore" under Microsoft.ConnectedVMwarevSphere/datastores; "Implements Get Datastores In A Subscription"' reason: CRUD over VMware vSphere datastores and HybridData data stores — storage infrastructure resource management within the cloud platform. - tag: ElasticSans spec_file: microsoft-azure-elasticsans-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: description "APIs for ElasticSan operations"; PUT/PATCH/DELETE ".../Microsoft.ElasticSan/elasticSans/{elasticSanName}"; schemas ElasticSanUpdateProperties, ProvisioningState reason: Full create/update/delete/get lifecycle for Elastic SAN storage resources — provisioning and stewardship of cloud storage infrastructure. - tag: Evaluations20220901Preview spec_file: microsoft-azure-evaluations20220901preview-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.75 evidence: '"Manages evaluations operations"; "Create Offline Evaluation", schemas PersonalizerError, PolicyContract, EvaluationResult' reason: Azure Personalizer offline policy evaluation — creating and inspecting offline evaluations of ranking policies is machine-learning model evaluation, i.e. AI/ML model lifecycle management. Not an experimentation product-telemetry surface of a SaaS product. - tag: EvaluationsV1Dot1Preview1 spec_file: microsoft-azure-evaluationsv1dot1preview1-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.75 evidence: '"Manages counterfactual evaluation operations"; "Create Offline Evaluation", schemas PolicyResultSummary, PersonalizerError' reason: Counterfactual/offline evaluation of Personalizer learning policies — model evaluation within the AI/ML lifecycle, mapped to Artificial Intelligence Management. - tag: ForwardingRules spec_file: microsoft-azure-forwarding-rules-api-openapi.yml reanchored_from: microsoft-azure-forwardingrules-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: 'Microsoft.Network/dnsForwardingRulesets/{dnsForwardingRulesetName}/forwardingRules ... schemas: TargetDnsServer, ForwardingRuleProperties' reason: CRUD over DNS forwarding rules in Azure Network — network infrastructure configuration. - tag: Galleries spec_file: microsoft-azure-galleries-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: Microsoft.Compute/galleries/{galleryName} ... schemas Gallery, GalleryProperties, SharingProfile reason: Azure Compute Gallery (shared image gallery) resource CRUD — cloud compute infrastructure management. - tag: GalleryImageVersions spec_file: microsoft-azure-galleryimageversions-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: galleries/{galleryName}/images/{galleryImageName}/versions/{galleryImageVersionName} ... GalleryImageVersionStorageProfile, ReplicationStatus, TargetRegion reason: VM image version publishing and replication across regions — cloud compute image infrastructure management. - tag: GalleryImages spec_file: microsoft-azure-galleryimages-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: Microsoft.Compute/galleries/{galleryName}/images/{galleryImageName} ... RecommendedMachineConfiguration, GalleryImageIdentifier reason: VM gallery image definitions across Compute, DevTestLab and LabServices — cloud compute image/infrastructure management. - tag: GroupsOwners spec_file: microsoft-azure-groupsowners-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: POST /{tenantID}/groups/{objectId}/$links/owners — microsoftAzureGroupsAddowner; schema AddOwnerParameters reason: Adds and removes owners of directory groups in the tenant directory — directory group access administration, i.e. Identity & Access Management. - tag: HostPool spec_file: microsoft-azure-hostpool-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: providers/Microsoft.DesktopVirtualization/hostPools/{hostPoolName} — CreateOrUpdate, Delete, RetrieveRegistrationToken; schemas HostPool, AgentUpdateProperties, MaintenanceWindowProperties reason: Provisioning and lifecycle of Azure Virtual Desktop host pools (session-host compute pools, agent updates, maintenance windows) — cloud compute infrastructure management, not a business-domain capability. - tag: Hosts spec_file: microsoft-azure-hosts-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: providers/Microsoft.ConnectedVMwarevSphere/hosts/{hostName} — "Gets A Host", "Implements Get Hosts In A Subscription"; schemas Host, HostProperties, DatadogHost reason: CRUD and inventory over VMware/Arc-connected physical hosts (plus listing monitored hosts). This is compute infrastructure resource management. - tag: Instances spec_file: microsoft-azure-instances-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: PUT /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.IoTOperationsDataProcessor/instances/{instanceName}; InstanceListResult, ProvisioningState reason: ARM control-plane CRUD provisioning service instances (Dynamics 365 Fraud Protection, IoT Operations Data Processor) within subscriptions/resource groups — cloud infrastructure resource provisioning, not fraud detection itself. - tag: Invoices spec_file: microsoft-azure-invoices-api-openapi.yml capability_id: BC-4250.30 capability_id_l1: BC-4250 capability_name: Invoicing & Statement Management confidence: 0.75 evidence: 'GET /subscriptions/{subscriptionId}/providers/Microsoft.Billing/invoices ... schemas: Invoice, InvoiceProperties, DownloadUrl' reason: Operations retrieve and download billing invoices for a cloud subscription under Microsoft.Billing, i.e. invoice generation/delivery for a consumption-based subscription service. Maps to Invoicing & Statement Management; slight ambiguity as it is read-only retrieval rather than generation. - tag: LoadTests spec_file: microsoft-azure-load-tests-api-openapi.yml reanchored_from: microsoft-azure-loadtests-api-openapi.yml capability_id: BC-4220.50 capability_id_l1: BC-4220 capability_name: Capacity & Performance Management confidence: 0.75 evidence: 'Microsoft.LoadTestService/loadTests ... microsoftAzureLoadtestsCreateorupdate; schemas: LoadTestResource, LoadTestProperties' reason: Provisioning Azure Load Testing resources supports performance testing of services; maps to capacity & performance management, though these operations only manage the test resource itself. - tag: ManagedNetwork spec_file: microsoft-azure-managednetwork-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: '"Provisions The Managed Network Of A Machine Learning Workspace"; schemas OutboundRule, ManagedNetworkProvisionStatus' reason: Provisioning and outbound rule configuration of a workspace's managed network — network infrastructure configuration. - tag: ManagedNetworkGroups spec_file: microsoft-azure-managednetworkgroups-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: paths ".../Microsoft.ManagedNetwork/managedNetworks/{managedNetworkName}/managedNetworkGroups"; schema ManagedNetworkGroupProperties reason: CRUD over groupings of resources within an Azure Managed Network — network infrastructure topology configuration. - tag: ManagedNetworkPeeringPolicies spec_file: microsoft-azure-managednetworkpeeringpolicies-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: schema ManagedNetworkPeeringPolicy; path ".../managedNetworks/{managedNetworkName}/managedNetworkPeeringPolicies" reason: CRUD over network peering policies inside a managed virtual network — network connectivity configuration, part of IT infrastructure management. - tag: MeshGateways spec_file: microsoft-azure-meshgateways-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: '"Creates Or Updates A Gateway Resource", schemas HttpRouteConfig, TcpConfig, NetworkRef' reason: Service Fabric Mesh gateway resources are network ingress infrastructure objects (HTTP/TCP routing, network refs) — cloud compute/network infrastructure provisioning, i.e. IT Infrastructure Management. No business-domain reading fits. - tag: Modelmanagement spec_file: microsoft-azure-model-management-api-openapi.yml reanchored_from: microsoft-azure-modelmanagement-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.75 evidence: paths under "/modelmanagement/v1.0/.../Microsoft.MachineLearningServices/workspaces/{workspace}/services", "Create A Service", schemas CreateServiceRequest, ModelEnvironmentDefinition, EnvironmentImageRequest reason: Azure Machine Learning model-management surface for deploying models as scored services within an ML workspace — MLOps / AI model lifecycle. - tag: Namespaces spec_file: microsoft-azure-namespaces-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: '''Creates Updates A Notification Hub Namespace This Operation Is Idempotent''; schemas NamespaceResource, SharedAccessAuthorizationRuleProperties' reason: Provisioning of Notification Hubs namespaces and their access rules is cloud infrastructure resource management. - tag: OpenShiftClusters spec_file: microsoft-azure-openshiftclusters-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: Creates Or Updates A Openshift Cluster With The Specified Subscription, Resource Group And Resource Name; Lists Admin Kubeconfig Of An Openshift Cluster reason: Operations provision, update, delete and retrieve credentials for managed Red Hat OpenShift (Kubernetes) clusters, with MasterProfile/WorkerProfile/NetworkProfile/VMSize schemas — i.e. lifecycle management of cloud compute infrastructure, which is IT Infrastructure Management. Not a tenant/SaaS commercial concept, so BC-600.50 rather than the Software & Technology branch. - tag: Peerings spec_file: microsoft-azure-peerings-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: schemas BgpSession, DirectConnection, ExchangeConnection, PeeringSku on .../Microsoft.Peering/peerings/{peeringName} reason: BGP sessions and direct/exchange connections are plainly network infrastructure configuration in the cloud platform. - tag: PrivateEndpointConnectionOperations spec_file: microsoft-azure-privateendpointconnectionoperations-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: GET/PUT/DELETE ".../assessmentProjects/{projectName}/privateEndpointConnections/{privateEndpointConnectionName}" reason: Manages private endpoint connections for Azure Migrate assessment projects; purely cloud networking resource lifecycle, i.e. IT infrastructure management. - tag: Redis spec_file: microsoft-azure-redis-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: PUT .../Microsoft.Cache/Redis/{name}; "Redis Name Forcereboot"; schemas RedisResource, RedisFirewallRule, RedisAccessKeys reason: Provisioning and administration of Azure Cache for Redis instances (create, reboot, keys, firewall rules) — management of cloud compute/data infrastructure. - tag: RedisEnterprise spec_file: microsoft-azure-redisenterprise-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: PUT .../Microsoft.Cache/redisEnterprise/{clusterName}; schemas Cluster, ClusterProperties, DatabaseProperties, Sku reason: Lifecycle management of Redis Enterprise clusters and their databases in Azure — cloud infrastructure provisioning and administration. - tag: Resource Groups spec_file: microsoft-azure-resource-groups-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: '"Operations for managing resource groups"; ResourceGroups_CreateOrUpdate "Create or Update a Resource Group"; schema ResourceGroupProperties' reason: CRUD over Azure Resource Groups — the container construct for cloud infrastructure resources. Squarely cloud/IT infrastructure management. - tag: RoutingRuleCollections spec_file: microsoft-azure-routingrulecollections-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: PUT /.../providers/Microsoft.Network/networkManagers/{networkManagerName}/routingConfigurations/{configurationName}/ruleCollections/{ruleCollectionName}; schemas RoutingRuleCollection, NetworkManagerRoutingGroupItem reason: CRUD over Azure Network Manager routing rule collections — configuration of network routing infrastructure, i.e. IT infrastructure (network) management, not a business routing concept. - tag: RoutingRules spec_file: microsoft-azure-routing-rules-api-openapi.yml reanchored_from: microsoft-azure-routingrules-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: schemas RoutingRule, RoutingRuleNextHop, RoutingRuleRouteDestination under .../networkManagers/{networkManagerName}/routingConfigurations reason: Individual network routing rules (next hop, destination) inside Azure Network Manager routing configurations — network infrastructure configuration. - tag: RunArtifacts spec_file: microsoft-azure-runartifacts-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.75 evidence: '''Get Artifacts In A Container'' under .../MachineLearningServices/workspaces/.../experiments/{experimentName}/runs/{runId}/artifacts; schemas Artifact, ArtifactContentInformation' reason: Artifact storage for Azure ML experiment runs — supporting surface of the ML model lifecycle / MLOps. - tag: RunMetrics spec_file: microsoft-azure-runmetrics-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.75 evidence: '''Get All Run Metrics For The Specific Experiment''; schemas RunMetric, MetricSchema, BatchMetric under MachineLearningServices experiments' reason: Logging and querying of Azure ML experiment run metrics — model training/evaluation tracking within AI/ML lifecycle management. - tag: ServerGroups spec_file: microsoft-azure-server-groups-api-openapi.yml reanchored_from: microsoft-azure-servergroups-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: PUT .../Microsoft.DBForPostgreSql/serverGroupsv2/{serverGroupName}; schemas ServerGroupProperties, PostgreSQLVersion, MaintenanceWindow reason: CRUD over managed PostgreSQL (Citus) server groups, including version and maintenance window, is provisioning and stewardship of database infrastructure. - tag: StandbyContainerGroupPools spec_file: microsoft-azure-standbycontainergrouppools-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: 'PUT .../Microsoft.StandbyPool/standbyContainerGroupPools/{standbyContainerGroupPoolName}; schemas: StandbyContainerGroupPoolElasticityProfile, RefillPolicy, ContainerGroupProfile' reason: CRUD over pre-provisioned container group pools with elasticity profiles and refill policies — provisioning and capacity configuration of cloud compute infrastructure. - tag: StandbyVirtualMachinePools spec_file: microsoft-azure-standbyvirtualmachinepools-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: 'PUT .../Microsoft.StandbyPool/standbyVirtualMachinePools/{standbyVirtualMachinePoolName}; schemas: StandbyVirtualMachinePoolElasticityProfile, VirtualMachineState' reason: CRUD over standby virtual machine pools with elasticity profiles — provisioning and capacity configuration of cloud compute infrastructure. - tag: TrainingSet spec_file: microsoft-azure-trainingset-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.75 evidence: GET /trainingsets, POST /trainingsets/{id}:upload, schemas TrainingSet, Dataset, VoiceKind, AzureBlobContentSource reason: Manages training sets/datasets used to train custom (voice) models, i.e. ML model lifecycle assets — closest fit is AI/ML management. - tag: TrustedIdProviders spec_file: microsoft-azure-trustedidproviders-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: '.../Microsoft.DataLakeStore/accounts/{accountName}/trustedIdProviders/{trustedIdProviderName}; schemas TrustedIdProvider, CreateOrUpdateTrustedIdProviderParameters' reason: Configures trusted identity providers allowed to authenticate against a Data Lake Store account — identity and access management configuration. - tag: Users spec_file: microsoft-azure-users-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: 'PUT /users/{userId} ''Create A User In The Application'' ... DELETE /users/{userId} ''Delete A User'' ... schemas: RoleAssignment, Permission' reason: Create/update/delete of user accounts across application, DataBox Edge device and DevTest Lab scopes, with RoleAssignment and Permission schemas — user account and access administration (IAM). Slightly lower confidence because the tag aggregates several unrelated resource providers. - tag: VirtualMachineTemplates spec_file: microsoft-azure-virtualmachinetemplates-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: Microsoft Azure Gets A Virtual Machine Template; schemas VirtualMachineTemplateProperties_2, VirtualDisk, NetworkInterface reason: CRUD over VM templates in ConnectedVMware/SCVMM providers is management of compute infrastructure building blocks. - tag: VirtualNetworkLinks spec_file: microsoft-azure-virtualnetworklinks-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: PUT .../Microsoft.Network/privateDnsZones/{privateZoneName}/virtualNetworkLinks/{virtualNetworkLinkName} reason: Linking virtual networks to private DNS zones / forwarding rulesets is DNS and network infrastructure configuration. - tag: Volumes OnPrem Migration spec_file: microsoft-azure-volumes-onprem-migration-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: '''Microsoft Azure Start Migration Process'' — POST .../volumes/{volumeName}/createOnPremMigrationReplication' reason: Operations peer an on-prem cluster and replicate storage volume data into Azure NetApp storage — storage/infrastructure migration, not a business capability. - tag: Volumes Relocation spec_file: microsoft-azure-volumes-relocation-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: '''Microsoft Azure Relocate Volume'', ''Microsoft Azure Finalize Volume Relocation'', schema ''relocateVolumeRequest''' reason: Relocation of NetApp storage volumes between infrastructure — storage infrastructure operations. - tag: WebServices spec_file: microsoft-azure-web-services-api-openapi.yml reanchored_from: microsoft-azure-webservices-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.75 evidence: '''/providers/Microsoft.MachineLearning/webServices/{webServiceName}'' with schemas ''MachineLearningWorkspace'', ''RealtimeConfiguration'', ''ModuleAssetParameter'', ''WebServiceProperties''' reason: Despite the generic tag, the operations manage Azure Machine Learning web services — deployment and lifecycle of ML models as scoring endpoints, which is MLOps/AI model lifecycle management. - tag: apiTokens spec_file: microsoft-azure-api-tokens-api-openapi.yml reanchored_from: microsoft-azure-apitokens-api-openapi.yml capability_id: BC-4270.40 capability_id_l1: BC-4270 capability_name: Developer Identity & Credential Management confidence: 0.75 evidence: '"Create A New Api Token In The Application To Use In The Iot Central Public Api The Token Value Will Be Returned In The Response"; schemas ApiToken, RoleAssignment, Permission' reason: Operations issue and revoke API tokens (credentials) used to call the public API, which is developer credential management. Some overlap with IAM (BC-620.20), hence moderate confidence. - tag: customizationPolicies spec_file: microsoft-azure-customizationpolicies-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: '"Implements Get Of Customization Policies List" under Microsoft.VMwareCloudSimple/privateClouds; schemas CustomizationNicSetting, CustomizationIPSettings' reason: VM guest customization specs (hostname, NIC, IP settings) for private cloud VMs — infrastructure provisioning configuration, not a business policy capability. - tag: documentClassifiers spec_file: microsoft-azure-document-classifiers-api-openapi.yml reanchored_from: microsoft-azure-documentclassifiers-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.75 evidence: POST /documentClassifiers/{classifierId}:analyze ClassifyDocumentFromStream; schema DocumentClassifierDetails reason: Lifecycle (list/get/delete) and inference use of trained document-classification models in Azure Document Intelligence — an AI/ML model lifecycle surface, not a business document process. - tag: documentModels spec_file: microsoft-azure-document-models-api-openapi.yml reanchored_from: microsoft-azure-documentmodels-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.75 evidence: GET /documentModels ListModels; POST /documentModels/{modelId}:analyze AnalyzeDocumentFromStream; DELETE /documentModels/{modelId} reason: Management and inference invocation of document extraction models — AI/ML model inventory and lifecycle operations. - tag: text:detectGroundedness spec_file: microsoft-azure-text-detectgroundedness-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.75 evidence: 'POST /text:detectGroundedness — ''Detect Groundedness''; schemas: AnalyzeTextGroundednessResult, LLMResource, UngroundednessDetails' reason: Content-safety operation evaluating whether LLM output is grounded in source material — a responsible-AI guardrail, which falls under Artificial Intelligence Management. No other candidate capability fits an LLM groundedness check. - tag: vpnLinkConnections spec_file: microsoft-azure-vpnlinkconnections-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: POST .../Microsoft.Network/vpnGateways/{gatewayName}/vpnConnections/{connectionName}/vpnLinkConnections/{linkConnectionName}/resetconnection reason: Resetting VPN gateway link connections is network infrastructure operation under Microsoft.Network, mapping to IT Infrastructure Management (network/cloud). - tag: PrivateEndpointConnectionProxyController spec_file: microsoft-azure-privateendpointconnectionproxycontroller-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.74 evidence: '"Microsoft Azure Create Or Update Private Endpoint Proxy"; "Validates Private Endpoint Connection Proxy"' reason: Lifecycle and validation of private endpoint proxy resources in Azure Migrate — network connectivity plumbing for cloud infrastructure. - tag: Alerts spec_file: microsoft-azure-alerts-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.72 evidence: '''Gets An Alert By Name''; POST .../managers/{managerName}/clearAlerts; POST .../devices/{deviceName}/sendTestAlertEmail; schemas AlertProperties, AlertSource, AlertErrorDetails' reason: Health/monitoring alerts raised by Azure infrastructure services (AD Hybrid Health, Data Box Edge, StorSimple) with clear and test-email operations. This is operational monitoring alerting — explicitly not financial-crime or fraud alerting. - tag: ApplicationOwners spec_file: microsoft-azure-applicationowners-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.72 evidence: '"Directory Objects That Are Owners Of The Application", POST /{tenantID}/applications/{applicationObjectId}/$links/owners; schema DirectoryObject' reason: Managing owner assignments on Azure AD directory application objects is directory/identity access administration, not a business ownership concept. - tag: Asset spec_file: microsoft-azure-asset-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.72 evidence: GET /modelmanagement/v1.0/subscriptions/.../Microsoft.MachineLearningServices/workspaces/{workspace}/assets Microsoft Azure Query The List Of Assets In A Workspace; schemas Asset, ArtifactDetails reason: Despite the generic 'Asset' tag, the paths sit under modelmanagement in Azure Machine Learning workspaces and manage model artefacts — ML model/artefact lifecycle (MLOps), i.e. Artificial Intelligence Management. Not fixed-asset accounting. - tag: Authoring spec_file: microsoft-azure-authoring-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.72 evidence: microsoftAzureConversationalanalysisauthoringTrain 'Post Authoring Analyze Conversations Projects Projectname :train'; schemas 'ConversationalAnalysisAuthoringTrainingMode', 'TextAnalysisAuthoringExportedModelManifest', 'ConversationalAnalysisAuthoringDeploymentJobState' reason: Operations create language-understanding projects, train models and manage model deployments — an ML model lifecycle surface, i.e. AI/ML model management rather than any business-domain capability. - tag: AvailabilitySets spec_file: microsoft-azure-availabilitysets-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: '''Gets An Availabilityset'', ''Implements Get Availabilitysets In A Resource Group''; schema ''AvailabilitySetProperties''' reason: CRUD over SCVMM availability sets — virtualisation/compute placement resources, i.e. IT infrastructure management. - tag: BackupVaults spec_file: microsoft-azure-backup-vaults-api-openapi.yml reanchored_from: microsoft-azure-backupvaults-api-openapi.yml capability_id: BC-160.20 capability_id_l1: BC-160 capability_name: Disaster Recovery Management confidence: 0.72 evidence: PUT/DELETE/PATCH /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.DataProtection/backupVaults/{vaultName} — BackupVaultResource, SoftDeleteSettings, CrossRegionRestoreSettings reason: Lifecycle management of Azure Data Protection backup vaults including cross-region restore and soft-delete settings — backup and restore capability for IT workloads. - tag: Blobs spec_file: microsoft-azure-blobs-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: Operations on blobs; PUT /{containerName}/{blob} Blob_Upload Microsoft Azure Upload a Blob reason: Object storage upload/download/delete primitives — cloud storage infrastructure. Arguably pure plumbing, but the storage-resource nature grounds IT infrastructure management. - tag: CloudAppliances spec_file: microsoft-azure-cloudappliances-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: POST .../Microsoft.StorSimple/managers/{managerName}/provisionCloudAppliance; schemas CloudApplianceConfiguration, VmImage reason: Provisioning and listing supported configurations of StorSimple cloud storage appliances — compute/storage infrastructure provisioning, squarely IT Infrastructure Management. - tag: ComputeNodes spec_file: microsoft-azure-computenodes-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: '"Removes Compute Nodes From The Specified Pool", "Restarts The Specified Compute Node", "Reinstalls The Operating System On The Specified Compute Node"' reason: Lifecycle and administration of compute nodes in a Batch pool (reboot, reimage OS, remove from pool, remote login settings) is management of compute infrastructure, not a business-domain capability. - tag: Custom spec_file: microsoft-azure-custom-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.72 evidence: '"Train Custom Model", "Get Custom Model", "Copy Custom Model", "Analyze Form", schemas TrainResult, TrainSourceFilter' reason: Form Recognizer custom model lifecycle — training, retrieval, deletion, copying and inference with ML models. That is AI/ML model lifecycle management (MLOps), the closest honest fit; scored moderately because the tag name itself is generic. - tag: DeploymentSettings spec_file: microsoft-azure-deployment-settings-api-openapi.yml reanchored_from: microsoft-azure-deploymentsettings-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: 'providers/Microsoft.AzureStackHCI/clusters/{clusterName}/deploymentSettings ... schemas: PhysicalNodes, NetworkController, Storage, ScaleUnits' reason: Configures physical cluster deployment (nodes, storage, network controller) for Azure Stack HCI — compute/storage/network infrastructure configuration. - tag: Environments spec_file: microsoft-azure-environments-api-openapi.yml capability_id: BC-4210.20 capability_id_l1: BC-4210 capability_name: Environment Management confidence: 0.72 evidence: PUT /projects/{projectName}/users/{userId}/environments/{environmentName} 'CreateOrReplaceEnvironment'; .../Microsoft.DevTestLab/labs/{labName}/users/{userName}/environments reason: Create, list and delete developer/test environments in Dev Center and DevTest Labs — provisioning and lifecycle of non-production environments. - tag: Managed CCF spec_file: microsoft-azure-managed-ccf-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: '"Creates A Managed Ccf", "Performs The Backup Operation On A Managed Ccf Resource"; schemas NodeCount, DeploymentType, RunningState' reason: CRUD plus backup/restore of a managed Confidential Consortium Framework service instance — provisioning and lifecycle of managed cloud infrastructure resources. - tag: ModelInference spec_file: microsoft-azure-modelinference-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.72 evidence: PUT /model-inference/models/microsoft-biomass/infer-data/{jobId}; schemas BiomassModelJob, SoilMoistureModelJob reason: Creates and polls inference jobs against pre-built ML models. This is operational AI/ML model execution, fitting Artificial Intelligence Management; the agriculture domain of the models has no matching capability in the frame. - tag: ModelV1Dot1Preview3 spec_file: microsoft-azure-modelv1dot1preview3-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.72 evidence: '"Manages reinforcement learning configuration operations"; GET /model, PUT /model "Put The Digitally Signed Model File", DELETE /model "Reset Model", schema PersonalizerError' reason: Operations manage the lifecycle of a machine-learning (Personalizer reinforcement-learning) model artefact — import, reset, inspect properties — which is AI/ML model lifecycle management rather than any business-domain capability. - tag: Monitors spec_file: microsoft-azure-monitors-api-openapi.yml capability_id: BC-4220.20 capability_id_l1: BC-4220 capability_name: Observability Management confidence: 0.72 evidence: '"/providers/Dynatrace.Observability/monitors/{monitorName}", "List The Resources Currently Being Monitored By The Dynatrace Monitor Resource", "Returns The Payload That Needs To Be Passed In The Request Body For Installing Dynatrace Agent On A Vm"' reason: Provisions and configures third-party observability monitor resources (Dynatrace, New Relic) including agent installation payloads and monitored-resource listing — observability tooling management, not financial or other business monitoring. - tag: NetworkManagerActiveConnectivityConfigurations spec_file: microsoft-azure-networkmanageractiveconnectivityconfigurations-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: POST .../Microsoft.Network/networkManagers/{networkManagerName}/listActiveConnectivityConfigurations; schemas ActiveConnectivityConfiguration reason: Lists active network connectivity configurations applied by Azure Network Manager — cloud network infrastructure configuration, i.e. IT Infrastructure Management. No business-domain capability involved. - tag: NetworkManagerEffectiveConnectivityConfiguration spec_file: microsoft-azure-networkmanagereffectiveconnectivityconfiguration-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: POST .../virtualNetworks/{virtualNetworkName}/listNetworkManagerEffectiveConnectivityConfigurations reason: Reports the effective connectivity configuration on a virtual network — cloud network infrastructure management. - tag: PeerAsns spec_file: microsoft-azure-peerasns-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: PUT /subscriptions/{subscriptionId}/providers/Microsoft.Peering/peerAsns/{peerAsnName} — schemas PeerAsn, PeerAsnProperties, ContactInfo reason: Registration and lifecycle of peer Autonomous System Numbers under Microsoft.Peering is network infrastructure provisioning, i.e. cloud/network infrastructure management, not a banking or industry business capability. - tag: PeeringServices spec_file: microsoft-azure-peeringservices-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: PUT/PATCH/DELETE .../providers/Microsoft.Peering/peeringServices/{peeringServiceName} — schemas PeeringService, PeeringServiceProperties reason: Lifecycle management of Azure Peering Service resources — provisioning of network connectivity infrastructure. - tag: PostRules spec_file: microsoft-azure-postrules-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.72 evidence: PUT /providers/PaloAltoNetworks.Cloudngfw/globalRulestacks/{globalRulestackName}/postRules/{priority}; schemas RuleEntry, SourceAddr, DestinationAddr, DecryptionRuleTypeEnum, RuleCounter reason: Management of next-generation firewall rulestack rules (source/destination, action, decryption, hit counters) — cybersecurity control configuration; sub-capability ambiguous between security architecture and operational controls. - tag: PreRules spec_file: microsoft-azure-prerules-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.72 evidence: PUT /providers/PaloAltoNetworks.Cloudngfw/globalRulestacks/{globalRulestackName}/preRules/{priority}; schemas RuleEntry, SourceAddr, DestinationAddr, RuleCounter reason: Firewall rulestack pre-rule configuration and hit-counter management — cybersecurity control administration; specific sub-capability not clearly determined. - tag: PrivateEndpointConnectionProxies spec_file: microsoft-azure-privateendpointconnectionproxies-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: schemas "PrivateLinkServiceProxy", "GroupConnectivityInformation", "RemotePrivateEndpoint" reason: Create/list/delete private endpoint connection proxies for Device Update accounts — internal private-link networking constructs, mapped to cloud/network infrastructure management. - tag: ReplicationFabrics spec_file: microsoft-azure-replicationfabrics-api-openapi.yml capability_id: BC-160.20 capability_id_l1: BC-160 capability_name: Disaster Recovery Management confidence: 0.72 evidence: '"Creates An Azure Site Recovery Fabric" and "Perform Failover Of The Process Server"' reason: Manages ASR fabrics including failover of the process server and consistency checks — clearly the orchestration substrate for IT disaster recovery. - tag: ReplicationPolicies spec_file: microsoft-azure-replication-policies-api-openapi.yml reanchored_from: microsoft-azure-replicationpolicies-api-openapi.yml capability_id: BC-160.20 capability_id_l1: BC-160 capability_name: Disaster Recovery Management confidence: 0.72 evidence: GET .../Microsoft.RecoveryServices/vaults/{resourceName}/replicationPolicies — "Gets The List Of Replication Policies"; schemas CreatePolicyInput, PolicyProviderSpecificDetails reason: These operations manage replication policies inside Azure Recovery Services vaults (Azure Site Recovery), i.e. the policy configuration governing replication for IT disaster recovery. That realises IT/operational disaster recovery capability rather than any generic policy-management or banking capability. Confidence tempered because the tag alone is a configuration surface within the broader DR service. - tag: ServerSecurityAlertPolicies spec_file: microsoft-azure-serversecurityalertpolicies-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.72 evidence: '"Servers Servername Securityalertpolicies"; schema "SecurityAlertPolicyProperties", "ServerSecurityAlertPolicy"' reason: Creates and reads threat-detection (security alert) policies on a managed database server, i.e. configuring security threat detection and alerting for infrastructure. - tag: SessionHostConfiguration spec_file: microsoft-azure-sessionhostconfiguration-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: schemas ImageInfoProperties, NetworkInfoProperties, DiskInfoPatchProperties, ActiveDirectoryInfoProperties under "sessionHostConfigurations/default" reason: Defines image, disk, network and directory settings for virtual desktop session hosts — configuration of compute/network infrastructure. - tag: SharedGalleries spec_file: microsoft-azure-sharedgalleries-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: GET /subscriptions/{subscriptionId}/providers/Microsoft.Compute/locations/{location}/sharedGalleries with schema SharedGallery, PirSharedGalleryResource reason: Read access to Microsoft.Compute shared image galleries — VM image catalogue for provisioning compute, i.e. cloud infrastructure management. - tag: StorageSyncServices Resource spec_file: microsoft-azure-storagesyncservices-resource-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: PUT/GET/PATCH/DELETE .../Microsoft.StorageSync/storageSyncServices/{storageSyncServiceName}; schemas StorageSyncService, StorageSyncServiceProperties reason: CRUD lifecycle of an Azure Storage Sync (file sync) service resource — provisioning and managing cloud storage infrastructure, which is IT Infrastructure Management. Some ambiguity as it is a cloud control-plane resource rather than an enterprise IT process. - tag: StorageTargets spec_file: microsoft-azure-storagetargets-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: PUT .../Microsoft.StorageCache/caches/{cacheName}/storageTargets/{storageTargetName}; POST .../flush, .../suspend, .../resume; schemas Nfs3Target, BlobNfsTarget, ClfsTarget reason: Manages storage back-ends attached to an Azure HPC Cache (NFS/blob targets, flush/suspend/resume) — configuration and operation of cloud storage infrastructure. - tag: TrafficControllerInterface spec_file: microsoft-azure-trafficcontrollerinterface-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: PUT /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.ServiceNetworking/trafficControllers/{trafficControllerName}; schemas TrafficController, TrafficControllerProperties, ProvisioningState reason: CRUD provisioning of Microsoft.ServiceNetworking traffic controller (application gateway/load-balancing) resources — cloud network infrastructure management, not any business-domain traffic concept. - tag: VmwareCollectorsOperations spec_file: microsoft-azure-vmwarecollectorsoperations-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: /providers/Microsoft.Migrate/assessmentProjects/{projectName}/vmwarecollectors; schemas VmwareCollector, CollectorAgentPropertiesBase reason: Manages VMware discovery collectors inside Azure Migrate assessment projects — infrastructure discovery/assessment tooling for migration, an IT infrastructure management concern. - tag: WebApplicationFirewallPolicies spec_file: microsoft-azure-webapplicationfirewallpolicies-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.72 evidence: PUT '/cdnWebApplicationFirewallPolicies/{policyName}' ... schemas 'WebApplicationFirewallPolicyPropertiesFormat', 'RateLimitRule', 'OwaspCrsExclusionEntry' reason: 'CRUD over WAF policies (OWASP CRS rules, rate limiting, match conditions) for CDN and Application Gateway — configuration of application-layer security controls, i.e. Cybersecurity Management. Not a policy-management (BC-130.20) capability: these are firewall rules, not corporate policies.' - tag: text:detectJailbreak spec_file: microsoft-azure-text-detectjailbreak-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.72 evidence: 'POST /text:detectJailbreak — ''Analyze Text Jailbreak''; schemas: JailbreakAnalysisResult, AnalyzeTextJailbreakOptions' reason: Detects jailbreak attempts against a language model — a responsible-AI safety control on model inputs, best placed under Artificial Intelligence Management rather than enterprise cybersecurity. - tag: AccessReviewInstanceResetDecisions spec_file: microsoft-azure-accessreviewinstanceresetdecisions-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: POST .../accessReviewScheduleDefinitions/{scheduleDefinitionId}/instances/{id}/resetDecisions reason: Resetting decisions on an access review instance is an operation within the access recertification lifecycle, an IAM governance capability. - tag: AccessReviewInstanceStop spec_file: microsoft-azure-accessreviewinstancestop-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: POST .../accessReviewScheduleDefinitions/{scheduleDefinitionId}/instances/{id}/stop reason: Stopping an access review instance controls the lifecycle of an access recertification campaign — IAM governance. - tag: AccessReviewScheduleDefinitionStop spec_file: microsoft-azure-accessreviewscheduledefinitionstop-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: POST /subscriptions/{subscriptionId}/providers/Microsoft.Authorization/accessReviewScheduleDefinitions/{scheduleDefinitionId}/stop reason: Stopping a recurring access review schedule definition manages the access recertification programme, an Identity & Access Management activity. - tag: AppServiceEnvironments spec_file: microsoft-azure-appserviceenvironments-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Get The Used, Available, And Total Worker Capacity An App Service Environment"; "Move An App Service Environment To A Different Vnet"; schemas "StampCapacity", "WorkerPoolResource", "VirtualIPMapping"' reason: Operations provision isolated hosting infrastructure — worker pools, capacity, virtual IPs, VNet placement, DNS suffix — which is compute/network infrastructure management rather than dev/test environment stewardship. - tag: AppServicePlans spec_file: microsoft-azure-appserviceplans-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: PUT ".../Microsoft.Web/serverfarms/{name}" "Creates Or Updates An App Service Plan"; "Get The Maximum Number Of Hybrid Connections Allowed In An App Service Plan" reason: App Service Plans (serverfarms) are compute capacity/SKU allocations for hosting apps, including hybrid connection limits — cloud compute infrastructure management. 'Plans' here is a compute tier, not a commercial subscription plan. - tag: Appliances spec_file: microsoft-azure-appliances-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Gets A List Of Appliances In A Subscription", "Creates Or Updates An Appliance", "Returns The Cluster User Credential", schema HybridConnectionConfig, UpgradeGraph' reason: Microsoft.ResourceConnector appliances are hybrid infrastructure resource bridges with cluster credentials and upgrade graphs — provisioning and lifecycle of compute/cloud infrastructure, i.e. IT Infrastructure Management. - tag: Assistants spec_file: microsoft-azure-assistants-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.7 evidence: microsoftAzureCreateassistant "Post Assistants"; "Create A Thread"; schemas AssistantCreationOptions, runStepDetailsToolCallsFunctionObject reason: 'Full Azure OpenAI Assistants API: creating, configuring and running AI assistants, threads and runs. This realises Artificial Intelligence Management (AI model/agent lifecycle), not any customer-service business capability.' - tag: Authorizations spec_file: microsoft-azure-authorizations-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '''List Expressroute Circuit Authorizations In A Private Cloud''; schema ''ExpressRouteAuthorization''' reason: Despite the word 'Authorizations', these operations manage ExpressRoute circuit authorizations for a private cloud — network connectivity configuration, i.e. cloud infrastructure management, not IAM. - tag: AvailabilityGroupListeners spec_file: microsoft-azure-availabilitygrouplisteners-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: PUT .../Microsoft.SqlVirtualMachine/sqlVirtualMachineGroups/{...}/availabilityGroupListeners/{...}; schemas 'AvailabilityGroupListenerProperties', 'LoadBalancerConfiguration', 'AgReplica' reason: Manages SQL Server availability-group listeners and load-balancer configuration on virtual machines — database/compute infrastructure configuration. - tag: BackupEngines spec_file: microsoft-azure-backupengines-api-openapi.yml capability_id: BC-4220.60 capability_id_l1: BC-4220 capability_name: Disaster Recovery & Resilience confidence: 0.7 evidence: 'schemas: BackupEngineBaseResource, BackupEngineExtendedInfo; path .../Microsoft.RecoveryServices/vaults/{vaultName}/backupEngines' reason: Lists backup management servers (engines) registered to a Recovery Services vault — backup/recovery infrastructure inventory. - tag: BackupInstancesExtensionRouting spec_file: microsoft-azure-backupinstancesextensionrouting-api-openapi.yml capability_id: BC-4220.60 capability_id_l1: BC-4220 capability_name: Disaster Recovery & Resilience confidence: 0.7 evidence: 'GET /{resourceId}/providers/Microsoft.DataProtection/backupInstances; schemas: BackupInstanceResourceList, ProtectionStatusDetails' reason: Lists Data Protection backup instances for a resource — read surface over backup protection state; backup/restore capability though thin (single list op). - tag: BackupProtectedItems spec_file: microsoft-azure-backupprotecteditems-api-openapi.yml capability_id: BC-160.20 capability_id_l1: BC-160 capability_name: Disaster Recovery Management confidence: 0.7 evidence: GET .../Microsoft.RecoveryServices/vaults/{vaultName}/backupProtectedItems — schemas ProtectedItemResource, ProtectedItem reason: Lists items protected by Azure Recovery Services backup vaults; this is IT backup/disaster-recovery protection inventory, mapped to IT and operational disaster recovery rather than any business-domain capability. - tag: BackupSchedules spec_file: microsoft-azure-backupschedules-api-openapi.yml capability_id: BC-160.20 capability_id_l1: BC-160 capability_name: Disaster Recovery Management confidence: 0.7 evidence: GET/PUT/DELETE .../devices/{deviceName}/backupPolicies/{backupPolicyName}/schedules/{backupScheduleName} — BackupSchedule, ScheduleRecurrence reason: Manages recurring backup schedules under backup policies for storage devices — backup/restore operations of IT infrastructure. - tag: Backups spec_file: microsoft-azure-backups-api-openapi.yml capability_id: BC-4220.60 capability_id_l1: BC-4220 capability_name: Disaster Recovery & Resilience confidence: 0.7 evidence: '"Microsoft Azure Create A Backup", "Microsoft Azure Describe The Backup Under Backup Vault", POST .../backups/{backupName}/restoreFiles "Create A New Backup Restore Files Request"' reason: Operations create, list, delete and restore backups in backup vaults — squarely backup-and-restore / resilience operations rather than any business-domain capability. - tag: BusinessCaseOperations spec_file: microsoft-azure-businesscaseoperations-api-openapi.yml capability_id: BC-230.50 capability_id_l1: BC-230 capability_name: Business Case Management confidence: 0.7 evidence: POST .../businessCases/{businessCaseName}/compareSummary — "Get Compare Summary Report For Business Case"; "Get Download Url For The Business Case Report" reason: Full lifecycle (create, get, delete, compare, report download) of migration business cases with licensing and savings-option settings — development and evaluation of a business case. Scoped to IT migration rather than generic corporate business cases, so not fully certain. - tag: CloudServiceOperatingSystems spec_file: microsoft-azure-cloudserviceoperatingsystems-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: GET .../Microsoft.Compute/locations/{location}/cloudServiceOsFamilies; schemas OSVersion, OSFamilyListResult reason: Read-only catalogue of guest OS families/versions available for Azure Cloud Services compute — platform/infrastructure metadata, mapped to IT Infrastructure Management. - tag: CloudServiceRoleInstances spec_file: microsoft-azure-cloudserviceroleinstances-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: POST .../cloudServices/{cloudServiceName}/roleInstances/{roleInstanceName}/restart; .../reimage; .../rebuild; schema RoleInstanceInstanceView reason: Operational control of compute role instances (restart, reimage, rebuild, instance view) for Azure Cloud Services — 'Roles' here are compute deployment roles, not organisational roles. IT infrastructure/compute management. - tag: ClusterExtensions spec_file: microsoft-azure-clusterextensions-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: PUT .../Microsoft.KubernetesConfiguration/extensions/{extensionName} microsoftAzureExtensionsCreate; schemas ExtensionStatus, ScopeCluster, ScopeNamespace reason: Install, update and delete extensions on Kubernetes clusters — management of cloud compute platform infrastructure components. - tag: ClusterOperations spec_file: microsoft-azure-clusteroperations-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: /providers/Microsoft.DBforPostgreSQL/serverGroupsv2/{clusterName}/restart, /start, /stop, microsoftAzureClustersPromotereadreplica reason: Operational control (start/stop/restart/promote replica) of managed PostgreSQL database clusters — running database infrastructure, no business-domain meaning. - tag: Completions spec_file: microsoft-azure-completions-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.7 evidence: POST /deployments/{deployment-id}/completions 'Create a Text Completion'; description 'Operations for text completions' reason: Azure OpenAI inference endpoint invoking a deployed language model; closest fit is AI/ML model lifecycle and serving under Artificial Intelligence Management, though this is model consumption rather than governance. - tag: ConnectivityConfigurations spec_file: microsoft-azure-connectivityconfigurations-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: PUT .../Microsoft.Network/networkManagers/{networkManagerName}/connectivityConfigurations/{configurationName}; schemas ConnectivityConfigurationProperties, Hub, connectivityGroupItem reason: Manages Azure Virtual Network Manager connectivity configurations (hub/mesh network topology) — network infrastructure design and provisioning, squarely IT Infrastructure Management. - tag: Costs spec_file: microsoft-azure-costs-api-openapi.yml capability_id: BC-600.80 capability_id_l1: BC-600 capability_name: IT Financial Management confidence: 0.7 evidence: schemas LabCostSummaryProperties, TargetCostProperties, PercentageCostThresholdProperties, LabResourceCostProperties reason: DevTest Lab cost objects with target costs and percentage cost thresholds — tracking and controlling IT/cloud spend, which maps to IT Financial Management (spend, showback, cost optimisation) rather than corporate cost accounting. - tag: 'Custom Speech Accuracy Tests:' spec_file: microsoft-azure-custom-speech-accuracy-tests-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.7 evidence: POST /accuracytests "Creates A New Accuracy Test"; schemas Model, ModelKind, Dataset, TestDefinition reason: Operations create and manage accuracy tests of custom speech models against datasets — model validation within the ML model lifecycle, i.e. AI/ML management rather than generic software testing. - tag: 'Custom Speech Datasets for Model Adaptation:' spec_file: microsoft-azure-custom-speech-datasets-for-model-adaptation-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.7 evidence: GET /models/locales-equivalent aside, tag surface is "Datasets for Model Adaptation" with "Uploads And Creates A New Dataset By Getting The Data From A Specified Url" reason: Manages training/adaptation datasets feeding custom speech model training — training-data curation is part of the AI/ML model lifecycle (MLOps). - tag: CustomDomains spec_file: microsoft-azure-custom-domains-api-openapi.yml reanchored_from: microsoft-azure-customdomains-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: PUT .../providers/Microsoft.Cdn/profiles/{profileName}/endpoints/{endpointName}/customDomains/{customDomainName}; POST .../enableCustomHttps reason: Configuration of custom domains and HTTPS on Azure CDN endpoints is network/cloud infrastructure configuration. - tag: CustomResourceProvider spec_file: microsoft-azure-customresourceprovider-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: PUT /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.CustomProviders/resourceProviders/{resourceProviderName}, schemas CustomRPManifest, CustomRPRouteDefinition reason: Azure Resource Manager custom resource provider registration — cloud infrastructure/platform resource management, an IT capability, not a business-domain one. - tag: Databases spec_file: microsoft-azure-databases-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Operations for managing Cosmos DB databases"; Databases_Create "Create a Database"; microsoftAzureDatabasesListbycluster (Microsoft.Kusto/clusters)' reason: Provisioning and lifecycle of cloud database resources (Cosmos DB, Kusto, SQL) — platform/infrastructure management, mapped to IT Infrastructure Management. - tag: Diagnostics spec_file: microsoft-azure-diagnostics-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: '"Get Site Detector Response"; "Execute Analysis"; "diagnostics/diskInspection/run"; schemas DiagnosticDetectorResponse, AbnormalTimePeriod' reason: Runs detectors and analyses to troubleshoot web apps and compute disks — day-to-day IT operations monitoring and diagnostics. - tag: DisasterRecoveryConfigurations spec_file: microsoft-azure-disasterrecoveryconfigurations-api-openapi.yml capability_id: BC-160.20 capability_id_l1: BC-160 capability_name: Disaster Recovery Management confidence: 0.7 evidence: POST .../disasterRecoveryConfiguration/{disasterRecoveryConfigurationName}/forceFailoverAllowDataLoss microsoftAzureDisasterrecoveryconfigurationsFailoverallowdataloss reason: Operations create/read/delete disaster-recovery configurations for Azure SQL servers and trigger failover, which is IT disaster recovery configuration and execution. Could alternatively be read as SaaS platform resilience, hence not maximal confidence. - tag: DiskPoolZones spec_file: microsoft-azure-diskpoolzones-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: 'GET /subscriptions/{subscriptionId}/providers/Microsoft.StoragePool/locations/{location}/diskPoolZones; schemas: DiskPoolZoneInfo, AvailabilityZone, Sku' reason: Lists available storage-pool SKUs per availability zone — cloud storage infrastructure capability lookup, i.e. IT infrastructure (compute/storage/cloud) management. Single read-only op keeps confidence moderate. - tag: DnssecConfigs spec_file: microsoft-azure-dnssecconfigs-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: 'providers/Microsoft.Network/dnsZones/{zoneName}/dnssecConfigs/default ... schemas: DnssecConfig, SigningKey, DelegationSignerInfo' reason: Configures DNSSEC signing on DNS zones — network infrastructure configuration; has a security flavour but is fundamentally DNS zone infrastructure management. - tag: Endpoints spec_file: microsoft-azure-endpoints-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: Microsoft.Cdn/profiles/{profileName}/endpoints/{endpointName}/purge ... DigitalTwins/digitalTwinsInstances/{resourceName}/endpoints reason: CRUD, start/stop and content purge on CDN endpoints and Digital Twins routing endpoints — provisioning and operation of cloud infrastructure resources. - tag: ExpressRouteCrossConnectionArpTable spec_file: microsoft-azure-expressroutecrossconnectionarptable-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: POST /.../Microsoft.Network/expressRouteCrossConnections/{crossConnectionName}/peerings/{peeringName}/arpTables/{devicePath} — microsoftAzureExpressroutecrossconnectionsListarptable reason: Retrieving the ARP table of an ExpressRoute cross-connection peering is network infrastructure operation/diagnostics, squarely IT Infrastructure Management (compute, storage, network, cloud). No business-domain meaning. - tag: ExpressRouteCrossConnectionRouteTable spec_file: microsoft-azure-expressroutecrossconnectionroutetable-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: microsoftAzureExpressroutecrossconnectionsListroutestable on .../peerings/{peeringName}/routeTables/{devicePath} reason: Listing device route tables for an ExpressRoute peering is network infrastructure inspection; maps to IT Infrastructure Management, no business capability. - tag: ExpressRouteCrossConnectionRouteTableSummary spec_file: microsoft-azure-expressroutecrossconnectionroutetablesummary-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: 'schemas: ExpressRouteCrossConnectionRoutesTableSummary; POST .../routeTablesSummary/{devicePath}' reason: BGP route table summary for an ExpressRoute cross-connection — network device state, part of cloud network infrastructure management. - tag: ExpressRouteServiceProviders spec_file: microsoft-azure-expressrouteserviceproviders-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: GET /subscriptions/{subscriptionId}/providers/Microsoft.Network/expressRouteServiceProviders; schema ExpressRouteServiceProviderBandwidthsOffered reason: Read-only catalogue of connectivity providers and bandwidths available for ExpressRoute — network infrastructure planning metadata, not IT vendor contract management. - tag: FileServers spec_file: microsoft-azure-file-servers-api-openapi.yml reanchored_from: microsoft-azure-fileservers-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: microsoftAzureFileserversCreateorupdate on .../Microsoft.StorSimple/managers/{managerName}/devices/{deviceName}/fileservers, plus microsoftAzureFileserversBackupnow and ListMetrics; schemas FileServerProperties, MetricDefinition reason: Lifecycle management (create/update/delete), backup and metrics for StorSimple file server appliances — provisioning and running storage infrastructure, i.e. IT infrastructure management. - tag: FluidRelayServers spec_file: microsoft-azure-fluidrelayservers-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: Microsoft Azure Create Or Update A Fluid Relay Server; Regenerate The Primary Or Secondary Key For This Server reason: Provisioning and lifecycle of a managed cloud service resource (servers, endpoints, access keys) — cloud infrastructure management. - tag: GET spec_file: microsoft-azure-get-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: Microsoft Azure Get The Non Security Related Metadata Of An Iot Hub; Microsoft Azure Get All The Iot Hubs In A Subscription reason: Generic HTTP-verb tag whose operations read IoT Hub resources, quotas and endpoint health — cloud infrastructure resource management, not a business capability of its own. - tag: Global spec_file: microsoft-azure-global-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: Gets All App Service Plans For A Subscription; Gets All Web Apps For A Subscription; Gets All Hostingenvironments App Service Environment For A Subscription reason: Subscription-wide inventory of App Service plans, web apps, hosting environments, certificates and geo-regions — management of cloud compute/hosting infrastructure. Could arguably be application management, so moderate confidence on the L2. - tag: GroupOwners spec_file: microsoft-azure-groupowners-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: GET /{tenantID}/groups/{objectId}/owners — 'Directory Objects That Are Owners Of The Group'; schemas DirectoryObjectListResult, DirectoryObject reason: Reads directory group ownership from the tenant directory (Azure AD graph). Group ownership administration is part of identity and access administration. - tag: GuestConfigurationConnectedVMwarevSphereAssignmentsReports spec_file: microsoft-azure-guestconfigurationconnectedvmwarevsphereassignmentsreports-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: 'guestConfigurationAssignments/{guestConfigurationAssignmentName}/reports ... schemas: AssignmentReportResourceComplianceReason, GuestConfigurationAssignmentReport' reason: Reads compliance reports for guest configuration assignments on VMware vSphere VMs — infrastructure configuration compliance reporting, part of IT operations management. Could arguably be security governance, but the operations are machine configuration state reporting. - tag: GuestConfigurationHCRPAssignments spec_file: microsoft-azure-guestconfigurationhcrpassignments-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: providers/Microsoft.HybridCompute/machines/{machineName}/providers/Microsoft.GuestConfiguration/guestConfigurationAssignments — Createorupdate/Get/Delete/List reason: Assigns and manages guest configuration (desired state) policies on hybrid-connected machines; this is IT operations/configuration management of infrastructure. - tag: HanaOnAzure spec_file: microsoft-azure-hanaonazure-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: Gets A List Of Sap Monitors In The Specified Subscription; Creates A Sap Monitor; Gets Properties Of A Provider Instance reason: Provisions and manages SAP monitors and provider instances on Azure — infrastructure monitoring resource management, IT operations. - tag: HcxEnterpriseSites spec_file: microsoft-azure-hcxenterprisesites-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: Create Or Update An Hcx Enterprise Site In A Private Cloud reason: CRUD over HCX enterprise sites within Azure VMware Solution private clouds — cloud/virtualisation infrastructure management. - tag: HypervClusterController spec_file: microsoft-azure-hypervclustercontroller-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: providers/Microsoft.OffAzure/hypervSites/{siteName}/clusters/{clusterName} — create/get/delete; schemas HypervCluster, HypervClusterProperties, HealthErrorDetailsDiscoveryScope reason: Registers and manages Hyper-V clusters within on-premises discovery sites (Azure Migrate/OffAzure). This is on-premises compute infrastructure inventory and management. - tag: HypervHostController spec_file: microsoft-azure-hypervhostcontroller-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: GET/PUT/DELETE .../hypervSites/{siteName}/hosts/{hostName}, schema HypervHost, HypervHostProperties reason: CRUD over Hyper-V virtualisation hosts registered to a discovery site — compute infrastructure management. - tag: HypervMachinesController spec_file: microsoft-azure-hypervmachinescontroller-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: GET .../hypervSites/{siteName}/machines/{machineName}, schemas HypervMachine, GuestOsDetails, StaticDiscovery reason: Inventory and property update of discovered Hyper-V virtual machines including OS and discovery state — server/compute infrastructure inventory management. - tag: InboundEndpoints spec_file: microsoft-azure-inboundendpoints-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: PUT .../Microsoft.Network/dnsResolvers/{dnsResolverName}/inboundEndpoints/{inboundEndpointName}; schemas IpConfiguration, InboundEndpointProperties reason: Lifecycle management of DNS resolver inbound endpoints with IP configurations — network infrastructure provisioning, which sits under IT Infrastructure Management (compute, storage, network, cloud). - tag: InfrastructureResources spec_file: microsoft-azure-infrastructure-resources-api-openapi.yml reanchored_from: microsoft-azure-infrastructureresources-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: PUT .../Microsoft.IntegrationSpaces/spaces/{spaceName}/infrastructureResources/{infrastructureResourceName}; schemas InfrastructureResource, ProvisioningState reason: CRUD lifecycle over Azure infrastructure resource records within an integration space — cloud infrastructure provisioning and management. - tag: IotDpsResource spec_file: microsoft-azure-iotdpsresource-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: Create Or Update The Metadata Of The Provisioning Service ... Get All The Provisioning Services In A Subscription reason: Lifecycle management of Azure IoT Hub Device Provisioning Service resources (SKUs, keys, private link) — provisioning and stewardship of cloud infrastructure services, i.e. IT Infrastructure Management. - tag: JitRequests spec_file: microsoft-azure-jitrequests-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: 'schemas: JitRequestProperties, JitAuthorizationPolicies, JitSchedulingPolicy, JitRequestState' reason: Just-in-time access request objects for Azure managed applications, carrying authorization policies and approval state — time-bound privileged access grants, which is Identity & Access Management. Some ambiguity as the surface is resource CRUD only. - tag: Keys spec_file: microsoft-azure-keys-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: 'POST /keys/{key-name}/create Keys_Create ... schemas: KeyVaultError, JsonWebKey, KeyReleasePolicy, RegenerateServiceKeysRequest' reason: Key Vault cryptographic key lifecycle plus service access-key regeneration — a security/credential management surface. Closest honest mapping is Identity & Access Management (credential/key issuance), though it is arguably key management infrastructure; confidence held moderate. - tag: LocalRules spec_file: microsoft-azure-localrules-api-openapi.yml capability_id: BC-620.50 capability_id_l1: BC-620 capability_name: Security Architecture Management confidence: 0.7 evidence: 'PaloAltoNetworks.Cloudngfw/localRulestacks/{localRulestackName}/localRules/{priority}; schemas: DecryptionRuleTypeEnum, RuleCounter, SourceAddr, DestinationAddr' reason: CRUD over Palo Alto cloud NGFW firewall rules is security control configuration; security architecture is the closest fit though it could also be seen as infrastructure config. - tag: LocalRulestacks spec_file: microsoft-azure-localrulestacks-api-openapi.yml capability_id: BC-620.50 capability_id_l1: BC-620 capability_name: Security Architecture Management confidence: 0.7 evidence: 'localRulestacks/{localRulestackName}/listAdvancedSecurityObjects ... schemas: securityServices, PredefinedUrlCategory, ListFirewallsResponse' reason: Managing Palo Alto Cloud NGFW rulestacks (firewall policy containers, security services, URL categories) is configuration of security controls. - tag: MachineExtensions spec_file: microsoft-azure-machineextensions-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: PUT .../Microsoft.ConnectedVMwarevSphere/virtualMachines/{virtualMachineName}/extensions/{extensionName} reason: Manages VM extensions on Arc-connected VMware/SCVMM virtual machines — configuration agents on compute infrastructure, i.e. IT infrastructure management. - tag: MachinesOperations spec_file: microsoft-azure-machinesoperations-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '".../Microsoft.Migrate/assessmentProjects/{projectName}/machines"; schemas Machine, ProcessorInfo, NetworkAdapter, Disk' reason: Read-only inventory of assessed machines with processor, disk and network adapter detail — compute/infrastructure asset inventory. Thin surface, hence moderate confidence. - tag: MaintenanceConfigurations spec_file: microsoft-azure-maintenanceconfigurations-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: schemas MaintenanceWindow, InputPatchConfiguration, InputLinuxParameters, InputWindowsParameters; "Create Or Update Configuration Record" reason: Defines maintenance windows and patch parameters for Azure resources — scheduled operational maintenance of IT estate, i.e. IT Operations Management. Could arguably be patch/vulnerability remediation, so not higher. - tag: MeshServiceReplicas spec_file: microsoft-azure-meshservicereplicas-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Lists All The Replicas Of A Service", schemas ContainerCodePackageProperties, ResourceRequirements' reason: Inspection of container service replicas within an application is compute/container infrastructure operations, not a business-domain capability. - tag: Microsoft Azure Azure ML Chat spec_file: microsoft-azure-microsoft-azure-azure-ml-chat-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.7 evidence: microsoftAzureChatCreatestreaming; schemas ChatCompletionChunk, StreamingChatCompletionOptions, ChatRole reason: 'Streaming chat completion inference against an Azure ML model endpoint — AI/ML model serving, mapped to Artificial Intelligence Management. Not customer service chat: no case, ticket or agent semantics.' - tag: NamedValue spec_file: microsoft-azure-namedvalue-api-openapi.yml capability_id: BC-4210.60 capability_id_l1: BC-4210 capability_name: Configuration & Secrets Management confidence: 0.7 evidence: POST .../namedValues/{namedValueId}/refreshSecret — 'Microsoft Azure ... Refreshsecret'; API Management named values store configuration values and secrets reason: API Management named values are runtime configuration/secret entries (listValue, refreshSecret), matching Configuration & Secrets Management rather than any business capability. - tag: NetworkExperimentProfiles spec_file: microsoft-azure-networkexperimentprofiles-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '''The configuration of Network Experiment profiles''; ''Creates An Networkexperiment Profile''' reason: Front Door network latency experiment profiles — network infrastructure configuration, not product A/B experimentation of software features. - tag: NetworkGroupMemberships_List spec_file: microsoft-azure-networkgroupmemberships-list-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: GET '.../virtualNetworks/{virtualNetworkName}/providers/Microsoft.Network/networkGroupMemberships' reason: Lists virtual network group memberships — network infrastructure inventory operation. - tag: NginxDeployment spec_file: microsoft-azure-nginxdeployment-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Create Or Update The Nginx Deployment"; "List All Nginx Deployments Under The Specified Resource Group"' reason: Provisioning and lifecycle of managed Nginx cloud resources — compute/network infrastructure provisioning. - tag: Node spec_file: microsoft-azure-node-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Gets The List Of Nodes In The Service Fabric Cluster"; "Restarts A Service Fabric Cluster Node"' reason: Operations on Service Fabric cluster compute nodes (health, activate/deactivate, restart) — cloud compute infrastructure management. - tag: NodeType spec_file: microsoft-azure-node-type-api-openapi.yml reanchored_from: microsoft-azure-nodetype-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Creates Or Updates A Service Fabric Node Type"; "Reimages One Or More Nodes On The Node Type"' reason: Manages node-type (VM scale set) definitions inside managed Service Fabric clusters — cloud compute infrastructure management. - tag: NspAccessRules spec_file: microsoft-azure-nspaccessrules-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: PUT .../Microsoft.Network/networkSecurityPerimeters/{networkSecurityPerimeterName}/profiles/{profileName}/accessRules/{accessRuleName}; schemas NspAccessRuleProperties, PerimeterBasedAccessRule reason: Creating and managing access rules on a network security perimeter is configuration of security controls, mapping to Cybersecurity Management; the specific sub-capability (security architecture vs access management) is ambiguous so only L1 asserted. - tag: OAuthProviders spec_file: microsoft-azure-oauth-providers-api-openapi.yml reanchored_from: microsoft-azure-oauthproviders-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: 'GET /oauth/providers ... schemas: OAuthProvider, OAuthProviderCascadeDeleteJob' reason: Operations manage OAuth provider registrations — identity/credential federation plumbing. Mapped to Identity & Access Management as the closest cross-industry IT capability; nothing banking-specific applies. - tag: OAuthTokens spec_file: microsoft-azure-oauth-tokens-api-openapi.yml reanchored_from: microsoft-azure-oauthtokens-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: POST /oauth/tokens/:connect microsoftAzureOauthtokensGetoauthconnectionlink, schema OAuthToken reason: Manages OAuth tokens/connections — authentication credential lifecycle, i.e. identity and access management plumbing rather than any business capability. - tag: OuContainer spec_file: microsoft-azure-oucontainer-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: List Of Oucontainers In Domainservice Instance / Create Oucontainer — Microsoft.Aad/domainServices reason: Manages organisational-unit containers within an Azure AD Domain Services managed domain instance — cloud infrastructure resource provisioning. Could arguably touch IAM, but the operations are CRUD on a managed domain-service infrastructure resource, so IT Infrastructure Management is the honest mapping. - tag: PATCH spec_file: microsoft-azure-patch-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: Update An Existing Iot Hubs Tags reason: Tag is an HTTP verb; the single operation updates IoT Hub resource metadata — cloud infrastructure resource management. - tag: PaymentMethods spec_file: microsoft-azure-payment-methods-api-openapi.yml reanchored_from: microsoft-azure-paymentmethods-api-openapi.yml capability_id: BC-4250.40 capability_id_l1: BC-4250 capability_name: Payment Collection & Dunning confidence: 0.7 evidence: GET /providers/Microsoft.Billing/billingAccounts/{billingAccountName}/billingProfiles/{billingProfileName}/paymentMethodLinks; schemas PaymentMethod, PaymentMethodLink, DetachPaymentMethodEligibilityResult reason: Listing, retrieving and detaching payment methods attached to billing accounts and billing profiles is payment-method management within the cloud subscription billing lifecycle, i.e. Payment Collection & Dunning. Not a banking payment rail — no initiation, clearing or settlement operations appear. - tag: PeeringServicePrefixes spec_file: microsoft-azure-peeringserviceprefixes-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: PUT .../peeringServices/{peeringServiceName}/prefixes/{prefixName} — schemas PeeringServicePrefix, PeeringServicePrefixEvent reason: CRUD over IP prefixes advertised through a peering service is network infrastructure configuration. - tag: Pipelines spec_file: microsoft-azure-pipelines-api-openapi.yml capability_id: BC-4210.10 capability_id_l1: BC-4210 capability_name: Continuous Integration Management confidence: 0.7 evidence: 'Providers Microsoft Devops Pipelines Pipelinename ... schemas: PipelineTemplate, PipelineStage, CodeRepository, BootstrapConfiguration' reason: Operations create/manage Microsoft.DevOps pipelines with code repository and pipeline stage/template schemas — CI build pipeline definition. Some ambiguity because the tag also covers IoT Operations Data Processor data pipelines, so confidence is moderated. - tag: PolicyListing spec_file: microsoft-azure-policylisting-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: Api To List The Purview Rbac Policies Based On A Scope; schemas PolicyDecisionRule, AadMember, PolicyMembers, Decision reason: Lists Purview RBAC access policies with AAD members and decision rules — access control/authorisation management, i.e. identity and access management. - tag: Pool Change spec_file: microsoft-azure-pool-change-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: POST .../Microsoft.NetApp/netAppAccounts/{accountName}/capacityPools/{poolName}/volumes/{volumeName}/poolChange — 'Change Pool For Volume' reason: Moves a NetApp storage volume between capacity pools — storage infrastructure administration. - tag: PrivateLinkResourceController spec_file: microsoft-azure-privatelinkresourcecontroller-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Microsoft Azure Get The List Of Private Link Resources"' reason: Lists/retrieves Private Link resources for migrate projects; cloud network resource metadata, i.e. IT infrastructure management, not a business capability. - tag: PrivateLinkResources spec_file: microsoft-azure-privatelinkresources-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: 'schemas: PrivateLinkResourceProperties, GroupIdInformation, ShareablePrivateLinkResourceType; GET .../configurationStores/{configStoreName}/privateLinkResources' reason: Broad set of ARM operations listing Private Link (private endpoint) resource groups across many Azure services — cloud network connectivity configuration, mapped to IT Infrastructure Management. - tag: Profiles spec_file: microsoft-azure-profiles-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: GET /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Cdn/profiles/{profileName} reason: Azure CDN profiles — creation, update, deletion and migration of content delivery network resources. This is cloud network infrastructure provisioning, not customer profiling; maps to IT Infrastructure Management. - tag: PurviewPolicies spec_file: microsoft-azure-purviewpolicies-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: '''Api To List The Purview Rbac Policies Based On A Scope'', schemas Policy, PolicyDecisionRule, AadMember' reason: Lists RBAC access policies and their member/decision rules — access control policy administration, mapping to Identity & Access Management. - tag: ReplicationProtectionContainers spec_file: microsoft-azure-replicationprotectioncontainers-api-openapi.yml capability_id: BC-160.20 capability_id_l1: BC-160 capability_name: Disaster Recovery Management confidence: 0.7 evidence: '"Switches Protection From One Container To Another Or One Replication Provider To Another"; "Adds A Protectable Item To The Replication Protection Container"' reason: Manages the containers that group replicated/protected workloads and switching of protection direction in Azure Site Recovery — IT disaster-recovery operations. Not a business capability beyond DR. - tag: ResourceManagementPrivateLink spec_file: microsoft-azure-resourcemanagementprivatelink-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: PUT/GET/DELETE .../providers/Microsoft.Authorization/resourceManagementPrivateLinks/{rmplName}, schemas ResourceManagementPrivateLinkEndpointConnections, ResourceManagementPrivateLinkLocation reason: Manages private-link endpoints for the Azure Resource Manager control plane — network/cloud infrastructure configuration. Despite the Microsoft.Authorization namespace, the objects are private-link network resources, not identity records. - tag: Restores spec_file: microsoft-azure-restores-api-openapi.yml capability_id: BC-160.20 capability_id_l1: BC-160 capability_name: Disaster Recovery Management confidence: 0.7 evidence: POST .../Microsoft.RecoveryServices/vaults/{vaultName}/.../recoveryPoints/{recoveryPointId}/restore microsoftAzureRestoresTrigger; schema RestoreRequest reason: Triggers a restore of a protected item from a recovery point in a Recovery Services vault — backup/restore execution, i.e. IT disaster recovery operations. - tag: RoleInstances spec_file: microsoft-azure-roleinstances-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: POST .../networkFunctions/{serviceKey}/roleInstances/{roleInstanceName}/start, /stop, /restart; schema NetworkFunctionRoleInstanceListResult reason: Start/stop/restart and inventory of network-function role instances (VM-like compute units) in Azure HybridNetwork — operational control of cloud compute/network infrastructure. - tag: Rules spec_file: microsoft-azure-rules-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: Create Or Update A Tag Rule Set For A Given Monitor Resource; schemas LogRules, MetricRules, MonitoringTagRules, FilteringTag reason: Configures which Azure resources send logs/metrics to Datadog/Elastic monitor resources — monitoring configuration within IT operations, not business rules. - tag: SecurityConnectors spec_file: microsoft-azure-securityconnectors-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: PUT "/providers/Microsoft.Security/securityConnectors/{securityConnectorName}", schemas "SecurityConnectorProperties", "EnvironmentData", "cloudOffering" reason: CRUD over Microsoft.Security security connectors that onboard cloud environments to the security service — cybersecurity tooling configuration. Kept at L1 because evidence does not distinguish governance/posture from detection. - tag: ServerRestart spec_file: microsoft-azure-serverrestart-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Providers Microsoft Dbformariadb Servers Servername Restart"' reason: Restarts a managed MariaDB database server instance — a compute/database infrastructure lifecycle operation performed by IT. - tag: SharedPrivateLinkResources spec_file: microsoft-azure-sharedprivatelinkresources-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: PUT .../searchServices/{searchServiceName}/sharedPrivateLinkResources/{sharedPrivateLinkResourceName}; schema SharedPrivateLinkResourceProperties reason: CRUD over private network link resources attached to Azure services — private networking configuration, squarely cloud/network infrastructure management. - tag: Shares spec_file: microsoft-azure-shares-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Lists All The Shares In A Data Box Edge Data Box Gateway Device"; "Creates A New Share Or Updates An Existing Share On The Device"' reason: '''Shares'' here are storage file shares on Data Box Edge devices, not equity shares — storage infrastructure provisioning. Classic homograph; operations confirm storage.' - tag: SmfDeployments spec_file: microsoft-azure-smfdeployments-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: PUT .../providers/Microsoft.MobilePacketCore/smfDeployments/{smfDeploymentName} microsoftAzureSmfdeploymentsCreateorupdate; schemas SmfDeploymentResourceProperties, ProvisioningState reason: CRUD provisioning of mobile packet core (SMF) network function deployments as Azure resources — provisioning and managing infrastructure components. - tag: Software Update Configuration Run spec_file: microsoft-azure-software-update-configuration-run-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: GET .../Microsoft.Automation/automationAccounts/{automationAccountName}/softwareUpdateConfigurationRuns; schemas softwareUpdateConfigurationRunTasks, softwareUpdateConfigurationRunProperties reason: Reporting on runs of Azure Automation software update (patching) configurations — day-to-day IT operations automation and monitoring of patch deployment. - tag: SqlPoolsV3 spec_file: microsoft-azure-sqlpoolsv3-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: PUT .../Microsoft.Synapse/workspaces/{workspaceName}/sqlPools/{sqlPoolName} ... microsoftAzureSqlpoolsv3Createorupdate; POST .../pause (Deactivate); POST .../resume (Activate) reason: Provisioning, scaling (SkuV3), pausing and resuming Synapse SQL pool compute resources — cloud infrastructure resource management. - tag: SqlServerRegistrations spec_file: microsoft-azure-sqlserverregistrations-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: PUT /subscriptions/.../providers/Microsoft.AzureData/sqlServerRegistrations/{sqlServerRegistrationName} microsoftAzureSqlserverregistrationsCreateorupdate reason: CRUD over registrations of SQL Server instances as managed Azure resources — registration/inventory of database infrastructure. - tag: SqlServers spec_file: microsoft-azure-sqlservers-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: 'PUT .../sqlServerRegistrations/{sqlServerRegistrationName}/sqlServers/{sqlServerName} microsoftAzureSqlserversCreateorupdate; schemas: SqlServerProperties' reason: Create/read/delete of SQL Server resources under a registration — management of database server infrastructure resources. - tag: StaticSites spec_file: microsoft-azure-staticsites-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: Microsoft Azure Creates A New Static Site In An Existing Resource Group, Or Updates An Existing Static Site; Microsoft Azure Gets All Static Site Builds For A Particular Static Site reason: Provisioning and administration of Azure Static Web Apps resources (sites, builds, linked backends, users). Cloud hosting infrastructure management; some overlap with deployment tooling hence not maximal confidence. - tag: StorageAccountCredentials spec_file: microsoft-azure-storageaccountcredentials-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: Microsoft Azure Gets All The Storage Account Credentials In A Data Box Edge Data Box Gateway Device; schema AsymmetricEncryptedSecret reason: Configures storage account credentials on Data Box Edge / StorSimple devices so they can attach cloud storage — storage/edge infrastructure configuration rather than enterprise identity management. - tag: StorageImportExport spec_file: microsoft-azure-storageimportexport-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: GET .../providers/Microsoft.ImportExport/jobs/{jobName}; schemas DeliveryPackageInformation, DriveBitLockerKey, ShippingInformation reason: Azure Import/Export jobs for shipping physical drives to transfer data into/out of Azure storage — bulk data-transfer operations against storage infrastructure. Not trade/logistics despite 'Import Export' wording. - tag: SuggestTagsAndRegionsApi spec_file: microsoft-azure-suggesttagsandregionsapi-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.7 evidence: 'POST /projects/{projectId}/tagsandregions/suggestions Suggest Tags And Regions For An Array Batch Of Untagged Images; schemas: Prediction, CustomVisionError' reason: Custom Vision model inference/labelling assistance for training image classifiers — AI/ML model lifecycle work rather than any business-domain capability. - tag: Test Base Package spec_file: microsoft-azure-test-base-package-api-openapi.yml capability_id: BC-4200.50 capability_id_l1: BC-4200 capability_name: Software Quality Engineering confidence: 0.7 evidence: Microsoft.TestBase/testBaseAccounts/{testBaseAccountName}/testTypes ... /packages/{packageName} (PUT/PATCH/DELETE); schemas PackageValidationResult, TestTypeResource, FlightingRingProperties reason: 'Azure Test Base: registering and configuring application test packages, test types and flighting rings for automated validation against OS builds — a software test/quality engineering surface, not a business-domain object. Some ambiguity vs IT application compatibility management, hence moderate confidence.' - tag: Test Result spec_file: microsoft-azure-test-result-api-openapi.yml capability_id: BC-4200.50 capability_id_l1: BC-4200 capability_name: Software Quality Engineering confidence: 0.7 evidence: /packages/{packageName}/testResults/{testResultName}/analysisResults; schemas TestExecutionStatus, TestResultAnalysisSummary, OSUpdateTestSummary reason: Retrieval of test summaries, test results and failure analysis results from Azure Test Base runs — test execution/defect analysis, i.e. software quality engineering. Moderate confidence given overlap with IT application management. - tag: TransactionNode spec_file: microsoft-azure-transactionnode-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: providers/Microsoft.Blockchain/blockchainMembers/{blockchainMemberName}/transactionNodes/{transactionNodeName}; schemas TransactionNode, FirewallRule, ApiKeyCollection reason: '''Transaction'' here is a blockchain service node resource, not a financial transaction; operations provision/delete nodes and rotate API keys — cloud infrastructure management.' - tag: Type spec_file: microsoft-azure-type-api-openapi.yml capability_id: BC-610 capability_id_l1: BC-610 capability_name: Information & Data Management confidence: 0.7 evidence: GET /atlas/v2/types/classificationdef/name/{name}; schemas AtlasBusinessMetadataDef, AtlasEntityDef, AtlasTypeDef reason: These are Purview/Atlas metadata type definitions (entity, classification, business metadata, relationship defs) that constitute the data catalogue's metadata model — Information & Data Management. Ambiguous between data governance and data architecture sub-capabilities, so only the L1 is asserted. - tag: Types spec_file: microsoft-azure-types-api-openapi.yml capability_id: BC-610 capability_id_l1: BC-610 capability_name: Information & Data Management confidence: 0.7 evidence: GET /types/termtemplatedef/name/{name}; GET /atlas/v2/types/businessmetadatadef/guid/{guid}; schemas AtlasTypeDefHeader, TermTemplateDef_2 reason: Same Purview/Atlas metadata type-definition surface, including glossary term templates and business metadata definitions — catalogue/metadata model management under Information & Data Management. L2 left null as evidence does not clearly name governance versus architecture. - tag: VMInstanceGuestAgents spec_file: microsoft-azure-vminstanceguestagents-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: PUT /{resourceUri}/providers/Microsoft.ConnectedVMwarevSphere/virtualMachineInstances/default/guestAgents/default — 'Implements Guestagent Put Method'; schemas GuestAgentProperties, GuestCredential reason: CRUD over guest agents installed on VMware vSphere virtual machine instances connected to Azure — management of compute infrastructure components, i.e. IT infrastructure management. No business-domain reading fits. - tag: VmwarePropertiesController spec_file: microsoft-azure-vmwarepropertiescontroller-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: POST .../vmwareSites/{siteName}/updateRunAsAccount, .../updateTags; schemas UpdateMachineTags, UpdateMachineRunAsAccount, MachineMetadata reason: Updates properties, tags and run-as accounts of discovered VMware machines at a site — administration of discovered server infrastructure metadata. - tag: Volumes OnPrem Migration Finalize spec_file: microsoft-azure-volumes-onprem-migration-finalize-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: POST .../volumes/{volumeName}/finalizeOnPremMigration 'Microsoft Azure Finalize Migration Process' reason: Single operation finalising on-prem to cloud storage volume migration — cloud storage infrastructure management. - tag: Volumes Replication spec_file: microsoft-azure-volumes-replication-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '''Microsoft Azure Break Volume Replication'', ''Microsoft Azure Get Volume Replication Status'', schema ''replicationStatus''' reason: Cross-region storage volume replication control for Azure NetApp volumes — storage infrastructure capability (could also be read as DR tooling, but it is infrastructure provisioning of replication relationships). - tag: deletedApplications spec_file: microsoft-azure-deletedapplications-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: '"Post Tenantid Deletedapplications Objectid Restore"; schemas Application, PasswordCredential, KeyCredential, OAuth2Permission, RequiredResourceAccess' reason: Azure AD (Graph) directory application object lifecycle — restore/list deleted app registrations with OAuth permissions and credentials, which is identity and access management. - tag: documentModels:compose spec_file: microsoft-azure-document-models-compose-api-openapi.yml reanchored_from: microsoft-azure-documentmodels-compose-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.7 evidence: POST /documentModels:compose ComposeModel; schemas ComposeDocumentModelRequest, ComponentDocumentModelDetails reason: Composes a new model from component trained models — AI/ML model lifecycle operation within Document Intelligence.