Azure Compute built-in role

Azure Arc VMware VM Contributor

Performs all Azure Arc-enabled VMware vSphere virtual-machine operations for the documented self-service workflow. It is a broad VM administration role for Arc-enabled VMware resources, not a general vCenter onboarding role or a least-privilege default.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: b748a06d-6150-4f8a-aaa9-ce3940cd96cb

Control-plane actions (56)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign the role on the Azure subscription or resource group where Arc-enabled VMware VMs are deployed and managed. Azure RBAC assignments at a parent scope are inherited by child resources. The role uses control-plane Actions only and has no DataActions, but broad VM lifecycle authority can affect workload integrity and availability.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign this role to the delegated VM operator at the narrowest subscription or resource-group scope containing the Arc-enabled VMware VMs. Pair it only with Azure Arc VMware Private Cloud User assignments on the exact resource pools, networks, datastores, and templates the operator needs.

Related roles (1)

Editorial sources (5)

Official Microsoft Learn documentation →