Azure Hybrid + multicloud built-in role
Azure Arc ScVmm Administrator role
Azure Arc ScVmm Administrator role performs all SCVMM actions and manages projected machines, extensions, run commands, patching, licenses, templates, networks, clouds, and management servers through Azure Arc-enabled SCVMM control-plane Actions. It has no DataActions, but its Azure operations can change the on-premises SCVMM resources projected through Azure Arc.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: a92dfd61-77f9-4aec-a531-19858b406c87
Control-plane actions (57)
Microsoft.ScVmm/*Microsoft.Insights/AlertRules/WriteMicrosoft.Insights/AlertRules/DeleteMicrosoft.Insights/AlertRules/ReadMicrosoft.Insights/AlertRules/Activated/ActionMicrosoft.Insights/AlertRules/Resolved/ActionMicrosoft.Insights/AlertRules/Throttled/ActionMicrosoft.Insights/AlertRules/Incidents/ReadMicrosoft.Resources/deployments/readMicrosoft.Resources/deployments/writeMicrosoft.Resources/deployments/deleteMicrosoft.Resources/deployments/cancel/actionMicrosoft.Resources/deployments/validate/actionMicrosoft.Resources/deployments/whatIf/actionMicrosoft.Resources/deployments/exportTemplate/actionMicrosoft.Resources/deployments/operations/readMicrosoft.Resources/deployments/operationstatuses/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/writeMicrosoft.Resources/subscriptions/resourcegroups/deployments/operations/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/operationstatuses/readMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Authorization/*/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/subscriptions/operationresults/readMicrosoft.ExtendedLocation/customLocations/ReadMicrosoft.ExtendedLocation/customLocations/deploy/actionMicrosoft.HybridCompute/machines/readMicrosoft.HybridCompute/machines/writeMicrosoft.HybridCompute/machines/deleteMicrosoft.HybridCompute/machines/UpgradeExtensions/actionMicrosoft.HybridCompute/machines/assessPatches/actionMicrosoft.HybridCompute/machines/installPatches/actionMicrosoft.HybridCompute/machines/extensions/readMicrosoft.HybridCompute/machines/extensions/writeMicrosoft.HybridCompute/machines/extensions/deleteMicrosoft.HybridCompute/operations/readMicrosoft.HybridCompute/locations/operationresults/readMicrosoft.HybridCompute/locations/operationstatus/readMicrosoft.HybridCompute/machines/patchAssessmentResults/readMicrosoft.HybridCompute/machines/patchAssessmentResults/softwarePatches/readMicrosoft.HybridCompute/machines/patchInstallationResults/readMicrosoft.HybridCompute/machines/patchInstallationResults/softwarePatches/readMicrosoft.HybridCompute/locations/updateCenterOperationResults/readMicrosoft.HybridCompute/machines/hybridIdentityMetadata/readMicrosoft.HybridCompute/osType/agentVersions/readMicrosoft.HybridCompute/osType/agentVersions/latest/readMicrosoft.HybridCompute/machines/runcommands/readMicrosoft.HybridCompute/machines/runcommands/writeMicrosoft.HybridCompute/machines/runcommands/deleteMicrosoft.HybridCompute/machines/licenseProfiles/readMicrosoft.HybridCompute/machines/licenseProfiles/writeMicrosoft.HybridCompute/machines/licenseProfiles/deleteMicrosoft.HybridCompute/licenses/readMicrosoft.HybridCompute/licenses/writeMicrosoft.HybridCompute/licenses/delete
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the resource group containing the Arc-enabled SCVMM management server and projected inventory. A broader assignment inherits complete SCVMM and Hybrid Compute administration to additional environments.
Common use cases (2)
- Administer the complete Arc-enabled SCVMM environment, including management servers, inventory, clouds, templates, networks, VMs, extensions, patching, and run commands.
- Troubleshoot or reconcile an enabled SCVMM VM when the operator needs both SCVMM and Arc-enabled server administration.
Prerequisites (2)
- The SCVMM management server must run a supported version, be connected to Azure Arc, and have a unique, running Azure Arc resource bridge and enabled inventory resources.
- An Owner or User Access Administrator at the target Azure scope is required to assign access; the SCVMM environment, network, static addresses, DNS, and bridge capacity must satisfy the onboarding requirements.
Best practices (2)
- Use the private-cloud and VM roles for self-service users and create a custom role when full SCVMM administration is unnecessary.
- Keep the resource bridge online and supported, use groups for recurring access, and use eligible or time-bound assignments for elevated operations.
Security considerations (2)
- The role can delete VMs and management resources, run commands and extensions that execute with privileged guest context, change patch and license state, and alter the SCVMM fabric exposed through Azure.
- These are Azure control-plane permissions, but the resource bridge translates authorized Azure operations into changes on the private SCVMM environment; an inherited assignment can therefore affect more on-premises resources.
Assignment guidance
Assign Azure Arc ScVmm Administrator role to the approved SCVMM operator or user group using the scope guidance above. Verify the resource bridge is healthy, test the intended operation, and remove or reduce access when the workflow ends.
Related roles (3)
- Azure Arc ScVmm Private Cloud User: Grants only the selected cloud, template, and network capabilities needed to deploy VMs.
- Azure Arc ScVmm VM Contributor: Provides all projected VM operations at the Azure deployment scope without all SCVMM fabric administration.
- Azure Arc ScVmm Private Clouds Onboarding: Limits the documented purpose to onboarding and deboarding VMM server instances.
Editorial sources (9)
- Azure built-in roles for Hybrid + multicloud - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Eligible and time-bound role assignments in Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Azure built-in roles for Azure Arc-enabled SCVMM →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Set up and manage self-service access to SCVMM resources →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Quickstart: Connect your System Center Virtual Machine Manager management server to Azure Arc →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.