Azure Hybrid + multicloud built-in role
Arc Gateway Manager
Creates, changes, and deletes Azure Arc gateway resources and manages the Hybrid Compute settings used to associate Arc-enabled resources. It uses Azure control-plane Actions only and has no DataActions; the gateway simplifies outbound endpoint configuration but does not become a data-plane authorization role for connected workloads.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: f6e92014-8af2-414d-9948-9b1abf559285
Control-plane actions (9)
Microsoft.HybridCompute/settings/writeMicrosoft.HybridCompute/settings/readMicrosoft.HybridCompute/gateways/readMicrosoft.HybridCompute/gateways/writeMicrosoft.HybridCompute/gateways/deleteMicrosoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the resource group containing the Arc gateway and on the narrowest parent scope that contains the Arc resources whose gateway association the operator must manage. Any Arc-enabled resource in the tenant can use a gateway, but Azure RBAC inheritance still controls which resources the principal can change.
Common use cases (2)
- Create and maintain Arc gateway resources that reduce the public endpoint allowlist required by Arc-enabled servers, Kubernetes clusters, or Azure Local.
- Associate supported Arc-enabled resources with a gateway and update the gateway plan as regional resource counts grow.
Prerequisites (2)
- Plan gateway count and control-plane region for the supported Arc resource population and ensure required network endpoints and resource providers are available.
- The assigning principal must identify the resource group for the gateway and the Arc resources whose association settings the operator will manage.
Best practices (2)
- Use a dedicated resource group for gateway resources, plan capacity by Azure region, and assign gateway management only to the connectivity platform team.
- Test failover and supported-resource connectivity, monitor gateway associations, and avoid subscription scope when one resource group contains the intended gateway estate.
Security considerations (2)
- Deleting or misconfiguring a gateway or an Arc association can interrupt Azure management connectivity for connected resources even though their local workloads may continue running.
- The role also manages deployments and classic alerts at the assigned scope, so it is broader than only reading gateway health.
Assignment guidance
Assign Arc Gateway Manager to the Arc connectivity team on the gateway resource group and the smallest scope containing the resources it must associate. Validate connectivity before and after changes and remove access from deployment identities when setup is complete.
Editorial sources (7)
- Azure built-in roles for Hybrid + multicloud - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Eligible and time-bound role assignments in Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Simplify network configuration requirements with Azure Arc gateway →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.