Azure Compute built-in role
Azure Arc VMware VM Contributor
Performs all Azure Arc-enabled VMware vSphere virtual-machine operations for the documented self-service workflow. It is a broad VM administration role for Arc-enabled VMware resources, not a general vCenter onboarding role or a least-privilege default.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: b748a06d-6150-4f8a-aaa9-ce3940cd96cb
Control-plane actions (56)
Microsoft.ConnectedVMwarevSphere/virtualmachines/*Microsoft.ConnectedVMwarevSphere/virtualmachineinstances/*Microsoft.Insights/AlertRules/WriteMicrosoft.Insights/AlertRules/DeleteMicrosoft.Insights/AlertRules/ReadMicrosoft.Insights/AlertRules/Activated/ActionMicrosoft.Insights/AlertRules/Resolved/ActionMicrosoft.Insights/AlertRules/Throttled/ActionMicrosoft.Insights/AlertRules/Incidents/ReadMicrosoft.Resources/deployments/readMicrosoft.Resources/deployments/writeMicrosoft.Resources/deployments/deleteMicrosoft.Resources/deployments/cancel/actionMicrosoft.Resources/deployments/validate/actionMicrosoft.Resources/deployments/whatIf/actionMicrosoft.Resources/deployments/exportTemplate/actionMicrosoft.Resources/deployments/operations/readMicrosoft.Resources/deployments/operationstatuses/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/writeMicrosoft.Resources/subscriptions/resourcegroups/deployments/operations/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/operationstatuses/readMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Authorization/*/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/subscriptions/operationresults/readMicrosoft.HybridCompute/machines/readMicrosoft.HybridCompute/machines/writeMicrosoft.HybridCompute/machines/deleteMicrosoft.HybridCompute/machines/UpgradeExtensions/actionMicrosoft.HybridCompute/machines/assessPatches/actionMicrosoft.HybridCompute/machines/installPatches/actionMicrosoft.HybridCompute/machines/extensions/readMicrosoft.HybridCompute/machines/extensions/writeMicrosoft.HybridCompute/machines/extensions/deleteMicrosoft.HybridCompute/operations/readMicrosoft.HybridCompute/locations/operationresults/readMicrosoft.HybridCompute/locations/operationstatus/readMicrosoft.HybridCompute/machines/patchAssessmentResults/readMicrosoft.HybridCompute/machines/patchAssessmentResults/softwarePatches/readMicrosoft.HybridCompute/machines/patchInstallationResults/readMicrosoft.HybridCompute/machines/patchInstallationResults/softwarePatches/readMicrosoft.HybridCompute/locations/updateCenterOperationResults/readMicrosoft.HybridCompute/machines/hybridIdentityMetadata/readMicrosoft.HybridCompute/osType/agentVersions/readMicrosoft.HybridCompute/osType/agentVersions/latest/readMicrosoft.HybridCompute/machines/runcommands/readMicrosoft.HybridCompute/machines/runcommands/writeMicrosoft.HybridCompute/machines/runcommands/deleteMicrosoft.HybridCompute/machines/licenseProfiles/readMicrosoft.HybridCompute/machines/licenseProfiles/writeMicrosoft.HybridCompute/machines/licenseProfiles/deleteMicrosoft.HybridCompute/licenses/readMicrosoft.HybridCompute/licenses/writeMicrosoft.HybridCompute/licenses/delete
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign the role on the Azure subscription or resource group where Arc-enabled VMware VMs are deployed and managed. Azure RBAC assignments at a parent scope are inherited by child resources. The role uses control-plane Actions only and has no DataActions, but broad VM lifecycle authority can affect workload integrity and availability.
Common use cases (2)
- Allow a platform or application team to deploy and manage Arc-enabled VMware virtual machines in an approved Azure resource group.
- Allow a delegated team to provision VMware VMs and change their size, disks, and network interfaces or delete them by using approved vSphere resources.
Prerequisites (2)
- The vCenter Server and the required resource pools, clusters or hosts, networks, datastores, and templates must already be connected to and enabled in Azure Arc.
- The assignee also needs Azure Arc VMware Private Cloud User on each vSphere compute, network, datastore, and template resource it is allowed to consume.
Best practices (3)
- Use a dedicated resource group for each delegated VMware estate and assign this broad role only at that boundary.
- Grant Azure Arc VMware Private Cloud User separately on only the underlying vSphere inventory objects the team may use.
- Review assignments regularly because VM creation, reconfiguration, and deletion can affect workload integrity, availability, and cost.
Security considerations (3)
- The documented workflow lets the assignee provision, resize, reconfigure disks and network interfaces, and delete Arc-enabled VMware VMs.
- Control-plane classification does not make the role low risk because VM lifecycle and hardware-profile changes can disrupt or destroy workloads.
- It does not itself grant access to every vSphere resource; the separate Private Cloud User assignments define which infrastructure objects can be consumed.
Assignment guidance
Assign this role to the delegated VM operator at the narrowest subscription or resource-group scope containing the Arc-enabled VMware VMs. Pair it only with Azure Arc VMware Private Cloud User assignments on the exact resource pools, networks, datastores, and templates the operator needs.
Related roles (1)
- Azure Arc VMware Private Cloud User: Microsoft documents this separate role as the permission to consume selected vSphere compute, network, datastore, and template resources while VM Contributor governs the Azure resource group where VMs are deployed.
Editorial sources (5)
- Azure built-in roles for Compute →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Set up and manage self-service access to VMware resources through Azure RBAC →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.