Azure Hybrid + multicloud built-in role
Azure Arc ScVmm Private Cloud User
Azure Arc ScVmm Private Cloud User uses selected SCVMM clouds, VM templates, and VM networks to deploy VMs without general SCVMM administration through Azure Arc-enabled SCVMM control-plane Actions. It has no DataActions, but its Azure operations can change the on-premises SCVMM resources projected through Azure Arc.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: c0781e91-8102-4553-8951-97c6d4243cda
Control-plane actions (34)
Microsoft.Insights/AlertRules/WriteMicrosoft.Insights/AlertRules/DeleteMicrosoft.Insights/AlertRules/ReadMicrosoft.Insights/AlertRules/Activated/ActionMicrosoft.Insights/AlertRules/Resolved/ActionMicrosoft.Insights/AlertRules/Throttled/ActionMicrosoft.Insights/AlertRules/Incidents/ReadMicrosoft.Resources/deployments/readMicrosoft.Resources/deployments/writeMicrosoft.Resources/deployments/deleteMicrosoft.Resources/deployments/cancel/actionMicrosoft.Resources/deployments/validate/actionMicrosoft.Resources/deployments/whatIf/actionMicrosoft.Resources/deployments/exportTemplate/actionMicrosoft.Resources/deployments/operations/readMicrosoft.Resources/deployments/operationstatuses/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/writeMicrosoft.Resources/subscriptions/resourcegroups/deployments/operations/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/operationstatuses/readMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Authorization/*/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/subscriptions/operationresults/readmicrosoft.scvmm/virtualnetworks/join/actionmicrosoft.scvmm/virtualnetworks/Readmicrosoft.scvmm/virtualmachinetemplates/clone/actionmicrosoft.scvmm/virtualmachinetemplates/Readmicrosoft.scvmm/clouds/deploy/actionmicrosoft.scvmm/clouds/ReadMicrosoft.ExtendedLocation/customLocations/ReadMicrosoft.ExtendedLocation/customLocations/deploy/actionMicrosoft.ExtendedLocation/customLocations/enabledresourcetypes/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign separately on each Arc-enabled SCVMM cloud, VM template, and VM network the user may consume, or on a resource group containing exactly those resources. The user also needs VM Contributor on the Azure resource group where VMs are deployed.
Common use cases (2)
- Give an application team self-service access to clone approved VM templates, join approved VM networks, and deploy into an approved SCVMM private cloud.
- Partition a shared SCVMM environment by assigning different user groups to different cloud, network, and template resource sets.
Prerequisites (2)
- The SCVMM management server must run a supported version, be connected to Azure Arc, and have a unique, running Azure Arc resource bridge and enabled inventory resources.
- An Owner or User Access Administrator at the target Azure scope is required to assign access; the SCVMM environment, network, static addresses, DNS, and bridge capacity must satisfy the onboarding requirements.
Best practices (2)
- Assign only on the SCVMM resources and Azure resource group required by the self-service workload; use a custom role for a smaller operation set.
- Keep the resource bridge online and supported, use groups for recurring access, and use eligible or time-bound assignments for elevated operations.
Security considerations (2)
- The role can consume cloud capacity, clone templates, join networks, and create Azure deployments on every SCVMM resource in its assignment scope.
- These are Azure control-plane permissions, but the resource bridge translates authorized Azure operations into changes on the private SCVMM environment; an inherited assignment can therefore affect more on-premises resources.
Assignment guidance
Assign Azure Arc ScVmm Private Cloud User to the approved SCVMM operator or user group using the scope guidance above. Verify the resource bridge is healthy, test the intended operation, and remove or reduce access when the workflow ends.
Related roles (2)
- Azure Arc ScVmm VM Contributor: Supplies the separate Azure resource-group permission needed to create and manage the deployed VMs.
- Azure Arc ScVmm Administrator role: Adds full SCVMM fabric and Arc machine administration.
Editorial sources (9)
- Azure built-in roles for Hybrid + multicloud - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Eligible and time-bound role assignments in Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Azure built-in roles for Azure Arc-enabled SCVMM →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Set up and manage self-service access to SCVMM resources →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Quickstart: Connect your System Center Virtual Machine Manager management server to Azure Arc →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.