Azure Hybrid + multicloud built-in role
Azure Arc ScVmm Private Clouds Onboarding
Azure Arc ScVmm Private Clouds Onboarding creates, updates, and deletes the projected VMM server resources needed to onboard or deboard a management server through Azure Arc-enabled SCVMM control-plane Actions. It has no DataActions, but its Azure operations can change the on-premises SCVMM resources projected through Azure Arc.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 6aac74c4-6311-40d2-bbdd-7d01e7c6e3a9
Control-plane actions (30)
microsoft.scvmm/vmmservers/Readmicrosoft.scvmm/vmmservers/Writemicrosoft.scvmm/vmmservers/DeleteMicrosoft.Insights/AlertRules/WriteMicrosoft.Insights/AlertRules/DeleteMicrosoft.Insights/AlertRules/ReadMicrosoft.Insights/AlertRules/Activated/ActionMicrosoft.Insights/AlertRules/Resolved/ActionMicrosoft.Insights/AlertRules/Throttled/ActionMicrosoft.Insights/AlertRules/Incidents/ReadMicrosoft.Resources/deployments/readMicrosoft.Resources/deployments/writeMicrosoft.Resources/deployments/deleteMicrosoft.Resources/deployments/cancel/actionMicrosoft.Resources/deployments/validate/actionMicrosoft.Resources/deployments/whatIf/actionMicrosoft.Resources/deployments/exportTemplate/actionMicrosoft.Resources/deployments/operations/readMicrosoft.Resources/deployments/operationstatuses/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/writeMicrosoft.Resources/subscriptions/resourcegroups/deployments/operations/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/operationstatuses/readMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Authorization/*/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/subscriptions/operationresults/readMicrosoft.ExtendedLocation/customLocations/ReadMicrosoft.ExtendedLocation/customLocations/deploy/action
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the resource group selected for the Arc resource bridge, custom location, and SCVMM management-server resource during the onboarding or deboarding window.
Common use cases (2)
- Connect a supported SCVMM 2019 or later management server to Azure Arc by deploying its one-to-one resource bridge and SCVMM extension.
- Deboard a VMM server instance from Azure after the affected projected resources and operational dependencies are reviewed.
Prerequisites (2)
- The SCVMM management server must run a supported version, be connected to Azure Arc, and have a unique, running Azure Arc resource bridge and enabled inventory resources.
- An Owner or User Access Administrator at the target Azure scope is required to assign access; the SCVMM environment, network, static addresses, DNS, and bridge capacity must satisfy the onboarding requirements.
Best practices (2)
- Grant this role only for the connect or deboard window, validate bridge and management-server health, then remove it.
- Keep the resource bridge online and supported, use groups for recurring access, and use eligible or time-bound assignments for elevated operations.
Security considerations (2)
- The role can create, change, and delete the VMM server projection and Azure deployments used for onboarding; deboarding removes Azure management of that SCVMM environment.
- These are Azure control-plane permissions, but the resource bridge translates authorized Azure operations into changes on the private SCVMM environment; an inherited assignment can therefore affect more on-premises resources.
Assignment guidance
Assign Azure Arc ScVmm Private Clouds Onboarding to the approved SCVMM operator or user group using the scope guidance above. Verify the resource bridge is healthy, test the intended operation, and remove or reduce access when the workflow ends.
Related roles (1)
- Azure Arc ScVmm Administrator role: Provides ongoing full administration after onboarding rather than only the VMM server lifecycle workflow.
Editorial sources (9)
- Azure built-in roles for Hybrid + multicloud - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Eligible and time-bound role assignments in Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Azure built-in roles for Azure Arc-enabled SCVMM →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Set up and manage self-service access to SCVMM resources →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Quickstart: Connect your System Center Virtual Machine Manager management server to Azure Arc →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.