Azure Hybrid + multicloud built-in role

Arc Gateway Manager

Creates, changes, and deletes Azure Arc gateway resources and manages the Hybrid Compute settings used to associate Arc-enabled resources. It uses Azure control-plane Actions only and has no DataActions; the gateway simplifies outbound endpoint configuration but does not become a data-plane authorization role for connected workloads.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: f6e92014-8af2-414d-9948-9b1abf559285

Control-plane actions (9)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the resource group containing the Arc gateway and on the narrowest parent scope that contains the Arc resources whose gateway association the operator must manage. Any Arc-enabled resource in the tenant can use a gateway, but Azure RBAC inheritance still controls which resources the principal can change.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Arc Gateway Manager to the Arc connectivity team on the gateway resource group and the smallest scope containing the resources it must associate. Validate connectivity before and after changes and remove access from deployment identities when setup is complete.

Editorial sources (7)

Official Microsoft Learn documentation →