Azure Hybrid + multicloud built-in role
Azure Arc ScVmm VM Contributor
Azure Arc ScVmm VM Contributor performs all projected SCVMM VM lifecycle actions, including create, update, delete, power, checkpoint, guest-agent, extension, patch, and run-command operations through Azure Arc-enabled SCVMM control-plane Actions. It has no DataActions, but its Azure operations can change the on-premises SCVMM resources projected through Azure Arc.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: e582369a-e17b-42a5-b10c-874c387c530b
Control-plane actions (58)
microsoft.scvmm/virtualmachines/*microsoft.scvmm/virtualMachineInstances/*Microsoft.Insights/AlertRules/WriteMicrosoft.Insights/AlertRules/DeleteMicrosoft.Insights/AlertRules/ReadMicrosoft.Insights/AlertRules/Activated/ActionMicrosoft.Insights/AlertRules/Resolved/ActionMicrosoft.Insights/AlertRules/Throttled/ActionMicrosoft.Insights/AlertRules/Incidents/ReadMicrosoft.Resources/deployments/readMicrosoft.Resources/deployments/writeMicrosoft.Resources/deployments/deleteMicrosoft.Resources/deployments/cancel/actionMicrosoft.Resources/deployments/validate/actionMicrosoft.Resources/deployments/whatIf/actionMicrosoft.Resources/deployments/exportTemplate/actionMicrosoft.Resources/deployments/operations/readMicrosoft.Resources/deployments/operationstatuses/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/writeMicrosoft.Resources/subscriptions/resourcegroups/deployments/operations/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/operationstatuses/readMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Authorization/*/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/subscriptions/operationresults/readMicrosoft.ExtendedLocation/customLocations/ReadMicrosoft.ExtendedLocation/customLocations/deploy/actionMicrosoft.HybridCompute/machines/readMicrosoft.HybridCompute/machines/writeMicrosoft.HybridCompute/machines/deleteMicrosoft.HybridCompute/machines/UpgradeExtensions/actionMicrosoft.HybridCompute/machines/assessPatches/actionMicrosoft.HybridCompute/machines/installPatches/actionMicrosoft.HybridCompute/machines/extensions/readMicrosoft.HybridCompute/machines/extensions/writeMicrosoft.HybridCompute/machines/extensions/deleteMicrosoft.HybridCompute/operations/readMicrosoft.HybridCompute/locations/operationresults/readMicrosoft.HybridCompute/locations/operationstatus/readMicrosoft.HybridCompute/machines/patchAssessmentResults/readMicrosoft.HybridCompute/machines/patchAssessmentResults/softwarePatches/readMicrosoft.HybridCompute/machines/patchInstallationResults/readMicrosoft.HybridCompute/machines/patchInstallationResults/softwarePatches/readMicrosoft.HybridCompute/locations/updateCenterOperationResults/readMicrosoft.HybridCompute/machines/hybridIdentityMetadata/readMicrosoft.HybridCompute/osType/agentVersions/readMicrosoft.HybridCompute/osType/agentVersions/latest/readMicrosoft.HybridCompute/machines/runcommands/readMicrosoft.HybridCompute/machines/runcommands/writeMicrosoft.HybridCompute/machines/runcommands/deleteMicrosoft.HybridCompute/machines/licenseProfiles/readMicrosoft.HybridCompute/machines/licenseProfiles/writeMicrosoft.HybridCompute/machines/licenseProfiles/deleteMicrosoft.HybridCompute/licenses/readMicrosoft.HybridCompute/licenses/writeMicrosoft.HybridCompute/licenses/delete
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the Azure subscription or resource group where the self-service VMs are deployed and managed. Pair it with Private Cloud User only on the approved SCVMM cloud, network, and template resources.
Common use cases (2)
- Let a self-service application team create, resize, attach disks and network interfaces, power-cycle, checkpoint, and delete its projected SCVMM VMs.
- Manage the Arc guest agent, extensions, patching, and run commands for the SCVMM VMs in an approved Azure resource group.
Prerequisites (2)
- The SCVMM management server must run a supported version, be connected to Azure Arc, and have a unique, running Azure Arc resource bridge and enabled inventory resources.
- An Owner or User Access Administrator at the target Azure scope is required to assign access; the SCVMM environment, network, static addresses, DNS, and bridge capacity must satisfy the onboarding requirements.
Best practices (2)
- Assign only on the SCVMM resources and Azure resource group required by the self-service workload; use a custom role for a smaller operation set.
- Keep the resource bridge online and supported, use groups for recurring access, and use eligible or time-bound assignments for elevated operations.
Security considerations (2)
- The role can delete or power off VMs, restore checkpoints, and use extensions or run commands that execute with privileged guest context, affecting workload integrity and availability.
- These are Azure control-plane permissions, but the resource bridge translates authorized Azure operations into changes on the private SCVMM environment; an inherited assignment can therefore affect more on-premises resources.
Assignment guidance
Assign Azure Arc ScVmm VM Contributor to the approved SCVMM operator or user group using the scope guidance above. Verify the resource bridge is healthy, test the intended operation, and remove or reduce access when the workflow ends.
Related roles (2)
- Azure Arc ScVmm Private Cloud User: Provides access to the selected SCVMM cloud, template, and network resources consumed during VM deployment.
- Azure Arc ScVmm Administrator role: Adds management-server, fabric, cloud, template, and network administration beyond VM lifecycle operations.
Editorial sources (9)
- Azure built-in roles for Hybrid + multicloud - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Eligible and time-bound role assignments in Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Azure built-in roles for Azure Arc-enabled SCVMM →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Set up and manage self-service access to SCVMM resources →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Quickstart: Connect your System Center Virtual Machine Manager management server to Azure Arc →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.