Azure Hybrid + multicloud built-in role

Azure Arc ScVmm VM Contributor

Azure Arc ScVmm VM Contributor performs all projected SCVMM VM lifecycle actions, including create, update, delete, power, checkpoint, guest-agent, extension, patch, and run-command operations through Azure Arc-enabled SCVMM control-plane Actions. It has no DataActions, but its Azure operations can change the on-premises SCVMM resources projected through Azure Arc.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: e582369a-e17b-42a5-b10c-874c387c530b

Control-plane actions (58)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the Azure subscription or resource group where the self-service VMs are deployed and managed. Pair it with Private Cloud User only on the approved SCVMM cloud, network, and template resources.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Azure Arc ScVmm VM Contributor to the approved SCVMM operator or user group using the scope guidance above. Verify the resource bridge is healthy, test the intended operation, and remove or reduce access when the workflow ends.

Related roles (2)

Editorial sources (9)

Official Microsoft Learn documentation →