Azure Hybrid + multicloud built-in role

Azure Arc ScVmm Private Clouds Onboarding

Azure Arc ScVmm Private Clouds Onboarding creates, updates, and deletes the projected VMM server resources needed to onboard or deboard a management server through Azure Arc-enabled SCVMM control-plane Actions. It has no DataActions, but its Azure operations can change the on-premises SCVMM resources projected through Azure Arc.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 6aac74c4-6311-40d2-bbdd-7d01e7c6e3a9

Control-plane actions (30)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the resource group selected for the Arc resource bridge, custom location, and SCVMM management-server resource during the onboarding or deboarding window.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Azure Arc ScVmm Private Clouds Onboarding to the approved SCVMM operator or user group using the scope guidance above. Verify the resource bridge is healthy, test the intended operation, and remove or reduce access when the workflow ends.

Related roles (1)

Common questions

When should I assign the Azure Arc ScVmm Private Clouds Onboarding Azure role?

Assign Azure Arc ScVmm Private Clouds Onboarding when you need to: Connect a supported SCVMM 2019 or later management server to Azure Arc by deploying its one-to-one resource bridge and SCVMM extension.; and Deboard a VMM server instance from Azure after the affected projected resources and operational dependencies are reviewed.. Practical scope: Assign on the resource group selected for the Arc resource bridge, custom location, and SCVMM management-server resource during the onboarding or deboarding window.

What permissions does the Azure Arc ScVmm Private Clouds Onboarding Azure role grant?

The role definition grants 30 combined control-plane and data-plane actions. Representative operations include: microsoft.scvmm/vmmservers/Read; microsoft.scvmm/vmmservers/Write; microsoft.scvmm/vmmservers/Delete; Microsoft.Insights/AlertRules/Write; Microsoft.Insights/AlertRules/Delete; and Microsoft.Insights/AlertRules/Read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure Arc ScVmm Private Clouds Onboarding Azure role?

Key considerations when assigning Azure Arc ScVmm Private Clouds Onboarding: The role can create, change, and delete the VMM server projection and Azure deployments used for onboarding; deboarding removes Azure management of that SCVMM environment.; and These are Azure control-plane permissions, but the resource bridge translates authorized Azure operations into changes on the private SCVMM environment; an inherited assignment can therefore affect more on-premises resources.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (9)

Official Microsoft Learn documentation →