Azure Security built-in role
App Compliance Automation Administrator
Administers the App Compliance Automation Tool for Microsoft 365 (ACAT) and the Azure resources used by its compliance-report workflow. The built-in definition has no DataActions, but its control-plane authority includes all ACAT operations, broad read access, storage-account and blob/file service configuration, blob-container changes, storage-account key listing, user delegation key generation, resource-group changes, deployments, policy evaluation, Microsoft Defender for Cloud automation changes, and security-provider registration or unregistration.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 0f37683f-2463-46b6-9ce7-9b788b988ba2
Control-plane actions (28)
Microsoft.AppComplianceAutomation/*Microsoft.Storage/storageAccounts/blobServices/writeMicrosoft.Storage/storageAccounts/fileservices/writeMicrosoft.Storage/storageAccounts/listKeys/actionMicrosoft.Storage/storageAccounts/writeMicrosoft.Storage/storageAccounts/blobServices/generateUserDelegationKey/actionMicrosoft.Storage/storageAccounts/readMicrosoft.Storage/storageAccounts/blobServices/containers/readMicrosoft.Storage/storageAccounts/blobServices/containers/writeMicrosoft.Storage/storageAccounts/blobServices/readMicrosoft.PolicyInsights/policyStates/queryResults/actionMicrosoft.PolicyInsights/policyStates/triggerEvaluation/actionMicrosoft.Resources/resources/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/subscriptions/resourceGroups/resources/readMicrosoft.Resources/subscriptions/resources/readMicrosoft.Resources/subscriptions/resourceGroups/deleteMicrosoft.Resources/subscriptions/resourceGroups/writeMicrosoft.Resources/tags/readMicrosoft.Resources/deployments/validate/actionMicrosoft.Security/automations/readMicrosoft.Resources/deployments/writeMicrosoft.Security/automations/deleteMicrosoft.Security/automations/writeMicrosoft.Security/register/actionMicrosoft.Security/unregister/action*/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
ACAT evaluates the cloud resources that define an application compliance boundary, and those resources can span multiple subscriptions. Microsoft requires the administrator permissions in every corresponding subscription. An assignment at subscription scope is inherited by its resource groups and resources; do not extend it to a management group unless administration of every inheriting subscription is intended.
Common use cases (2)
- Create, modify, repair, and delete ACAT compliance reports for applications that consume Microsoft 365 customer data.
- Operate ACAT assessment refreshes and the documented self-recovery workflow across every subscription included in a report.
Prerequisites (3)
- Identify every subscription whose cloud resources are included in the compliance report boundary.
- Microsoft documents App Compliance Automation Administrator together with Resource Policy Contributor for ACAT administrator operations in each corresponding subscription.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at each assignment scope.
Best practices (3)
- Grant the role only to the ACAT administrators responsible for the specified application reports, and review the separate Resource Policy Contributor assignment at the same time.
- Use dedicated groups or automation identities and avoid management-group scope when the reports cover only selected subscriptions.
- Disallow Shared Key authorization where supported, tightly constrain any generated user delegation SAS, and review resource-group or security-automation changes because the role is broader than report-only administration.
Security considerations (4)
- The role can list storage-account keys. Shared Key grants full access to storage-account data and can sign service or account SAS tokens even though the role definition has no DataActions.
- The role can request a user delegation key, but that key alone grants no blob data access. A resulting user delegation SAS is limited by both its encoded permissions and separate Blob Storage RBAC or POSIX ACL permissions held by the requester. SAS generation is not directly auditable.
- Its wildcard control-plane read permission exposes resource configuration throughout the assigned scope.
- The definition can change storage service and container configuration, create or delete resource groups, change Microsoft Defender for Cloud automations, and register or unregister the security provider, so it is a broad privileged administrator role rather than a least-privilege reporting role.
Assignment guidance
Assign this role only for ACAT administrator operations and only in the subscriptions represented by the application compliance report. Add the separately documented Resource Policy Contributor role, monitor account-key and user-delegation-key use plus repair actions, and use Azure Reader instead for principals that only view assessments or download reports.
Related roles (2)
- Resource Policy Contributor: Microsoft documents this as a separate role required with App Compliance Automation Administrator for ACAT administrator operations.
- Reader: Microsoft documents Azure Reader for ACAT read-only operations such as viewing assessments and downloading reports.
Editorial sources (7)
- Azure built-in roles for Security →
Supports: Description, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Troubleshooting guide for ACAT →
Supports: Practical scope, Common use cases, Prerequisites, Best practices, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Manage account access keys - Azure Storage →
Supports: Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Grant limited access to data with shared access signatures (SAS) →
Supports: Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.