Azure Management and governance built-in role
Advisor Recommendations Contributor (Assessments and Reviews)
Reads Azure Advisor assessment recommendations and accepted review recommendations and changes recommendation lifecycle state, including completed, postponed, dismissed, in-progress, and not-started states. It is a control-plane role with no DataActions and does not grant access to change the recommended resources.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 6b534d80-e337-47c4-864f-140f5c7f593d
Control-plane actions (4)
Microsoft.Advisor/recommendations/readMicrosoft.Advisor/recommendations/writeMicrosoft.Advisor/recommendations/available/actionMicrosoft.Advisor/conversations/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign at the subscription or resource group whose Advisor recommendations the reviewer owns; a parent assignment exposes and permits lifecycle changes for recommendations throughout inherited child scopes.
Common use cases (2)
- Triage assessment recommendations and record their approved lifecycle state after an engineering review.
- Manage Advisor recommendation conversations and track remediation progress without granting resource remediation permissions.
Prerequisites (2)
- Advisor must have recommendations or assessments available in the intended subscription or resource group.
- The assignee needs separate roles on target resources to implement any recommended change.
Best practices (2)
- Separate recommendation-state governance from the identities that modify production resources.
- Scope the assignment to the reviewed workload boundary and require a reason or ticket before dismissing or postponing a recommendation.
Security considerations (2)
- Changing recommendation state can hide or defer important cost, reliability, performance, operational-excellence, or security work even though the role cannot modify the resource itself.
- The role has control-plane recommendation writes and no data-plane access.
Assignment guidance
Assign to the team accountable for Advisor assessment governance at the workload resource group or subscription. Grant resource contributor roles separately and do not describe this recommendation-lifecycle role as permission to remediate resources.
Editorial sources (5)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Roles and permissions in Azure Advisor →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.