Azure Management and governance built-in role

Advisor Recommendations Contributor (Assessments and Reviews)

Reads Azure Advisor assessment recommendations and accepted review recommendations and changes recommendation lifecycle state, including completed, postponed, dismissed, in-progress, and not-started states. It is a control-plane role with no DataActions and does not grant access to change the recommended resources.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 6b534d80-e337-47c4-864f-140f5c7f593d

Control-plane actions (4)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign at the subscription or resource group whose Advisor recommendations the reviewer owns; a parent assignment exposes and permits lifecycle changes for recommendations throughout inherited child scopes.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign to the team accountable for Advisor assessment governance at the workload resource group or subscription. Grant resource contributor roles separately and do not describe this recommendation-lifecycle role as permission to remediate resources.

Common questions

When should I assign the Advisor Recommendations Contributor (Assessments and Reviews) Azure role?

Assign Advisor Recommendations Contributor (Assessments and Reviews) when you need to: Triage assessment recommendations and record their approved lifecycle state after an engineering review.; and Manage Advisor recommendation conversations and track remediation progress without granting resource remediation permissions.. Practical scope: Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign at the subscription or resource group whose Advisor recommendations the reviewer owns; a parent assignment exposes and permits lifecycle changes for recommendations throughout inherited child scopes.

What permissions does the Advisor Recommendations Contributor (Assessments and Reviews) Azure role grant?

The role definition grants 4 combined control-plane and data-plane actions. Representative operations include: Microsoft.Advisor/recommendations/read; Microsoft.Advisor/recommendations/write; Microsoft.Advisor/recommendations/available/action; and Microsoft.Advisor/conversations/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Advisor Recommendations Contributor (Assessments and Reviews) Azure role?

Key considerations when assigning Advisor Recommendations Contributor (Assessments and Reviews): Changing recommendation state can hide or defer important cost, reliability, performance, operational-excellence, or security work even though the role cannot modify the resource itself.; and The role has control-plane recommendation writes and no data-plane access.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →