Azure Compute built-in role

Azure Arc VMware VM Contributor

Performs all Azure Arc-enabled VMware vSphere virtual-machine operations for the documented self-service workflow. It is a broad VM administration role for Arc-enabled VMware resources, not a general vCenter onboarding role or a least-privilege default.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: b748a06d-6150-4f8a-aaa9-ce3940cd96cb

Control-plane actions (56)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign the role on the Azure subscription or resource group where Arc-enabled VMware VMs are deployed and managed. Azure RBAC assignments at a parent scope are inherited by child resources. The role uses control-plane Actions only and has no DataActions, but broad VM lifecycle authority can affect workload integrity and availability.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign this role to the delegated VM operator at the narrowest subscription or resource-group scope containing the Arc-enabled VMware VMs. Pair it only with Azure Arc VMware Private Cloud User assignments on the exact resource pools, networks, datastores, and templates the operator needs.

Related roles (1)

Common questions

When should I assign the Azure Arc VMware VM Contributor Azure role?

Assign Azure Arc VMware VM Contributor when you need to: Allow a platform or application team to deploy and manage Arc-enabled VMware virtual machines in an approved Azure resource group.; and Allow a delegated team to provision VMware VMs and change their size, disks, and network interfaces or delete them by using approved vSphere resources.. Practical scope: Assign the role on the Azure subscription or resource group where Arc-enabled VMware VMs are deployed and managed. Azure RBAC assignments at a parent scope are inherited by child resources. The role uses control-plane Actions only and has no DataActions, but broad VM lifecycle authority can affect workload integrity and availability.

What permissions does the Azure Arc VMware VM Contributor Azure role grant?

The role definition grants 56 combined control-plane and data-plane actions. Representative operations include: Microsoft.ConnectedVMwarevSphere/virtualmachines/*; Microsoft.ConnectedVMwarevSphere/virtualmachineinstances/*; Microsoft.Insights/AlertRules/Write; Microsoft.Insights/AlertRules/Delete; Microsoft.Insights/AlertRules/Read; and Microsoft.Insights/AlertRules/Activated/Action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure Arc VMware VM Contributor Azure role?

Key considerations when assigning Azure Arc VMware VM Contributor: The documented workflow lets the assignee provision, resize, reconfigure disks and network interfaces, and delete Arc-enabled VMware VMs.; Control-plane classification does not make the role low risk because VM lifecycle and hardware-profile changes can disrupt or destroy workloads.; and It does not itself grant access to every vSphere resource; the separate Private Cloud User assignments define which infrastructure objects can be consumed.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →