Azure Containers built-in role
Azure Arc Enabled Kubernetes Cluster User Role
Azure Arc Enabled Kubernetes Cluster User Role authorizes retrieval of the Cluster Connect user kubeconfig for Arc-enabled Kubernetes connected cluster through an Azure control-plane list-credential Action. The returned user kubeconfig establishes a connection and authentication context; Kubernetes authorization remains governed separately by Microsoft Entra, Azure RBAC, or Kubernetes RBAC. The role also writes ARM deployments, manages classic alert rules, and creates or updates Azure support tickets at the assigned scope.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 00493d72-78f6-4148-b6c5-d3ce8e4799dd
Control-plane actions (9)
Microsoft.Resources/deployments/writeMicrosoft.Resources/subscriptions/operationresults/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Kubernetes/connectedClusters/listClusterUserCredentials/actionMicrosoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Support/*Microsoft.Kubernetes/connectedClusters/listClusterUserCredential/action
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual Arc-enabled Kubernetes connected cluster. A resource-group or broader assignment is inherited by every matching resource below it and permits credential retrieval and the documented additional operation for each inherited cluster.
Common use cases (1)
- Allow an approved user or automation identity to obtain the user kubeconfig needed to connect to one Arc-enabled Kubernetes connected cluster.
Prerequisites (2)
- The Arc-enabled Kubernetes connected cluster must exist and the client must meet its network and Microsoft Entra authentication requirements.
- Assign an appropriate Kubernetes authorization role separately; credential retrieval alone does not define allowed Kubernetes API operations.
Best practices (2)
- Use Microsoft Entra user kubeconfig rather than shared local administrator credentials and keep the Azure assignment on the cluster resource.
- Protect kubeconfig files, avoid committing them to source control, revoke role or identity access when exposure is suspected, and remove temporary assignments promptly.
Security considerations (3)
- A kubeconfig can connect the holder to the cluster, but effective Kubernetes permissions depend on the platform authentication and Kubernetes authorization configuration.
- A broad inherited Azure assignment allows credential retrieval from multiple clusters.
- The deployment write, classic-alert wildcard, and support wildcard are broader Azure control-plane capabilities than kubeconfig retrieval alone.
Assignment guidance
Assign Azure Arc Enabled Kubernetes Cluster User Role directly on the Arc-enabled Kubernetes connected cluster to the identity that must retrieve the Cluster Connect user kubeconfig. Add the appropriate Kubernetes API role separately and validate credential retrieval and Kubernetes authorization independently; audit the additional control-plane operations as well.
Related roles (1)
- Azure Arc Kubernetes Viewer: The current Cluster Connect workflow pairs this credential-retrieval role with a separate Azure Arc Kubernetes authorization role and uses Viewer as its read-only example.
Editorial sources (7)
- Azure built-in roles for Containers - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Use Azure RBAC on Azure Arc-enabled Kubernetes clusters →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Use cluster connect to securely connect to Azure Arc-enabled Kubernetes clusters →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.