Azure Management and governance built-in role

Automation Contributor

Manages all Azure Automation account resources except Azure RBAC access. Its control-plane permissions also include deployments, monitoring configuration, support tickets, and Log Analytics shared-key retrieval. Permissions used by a runbook identity against target resources are separate from this human or management role.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: f353d9bd-d4a6-484e-a77a-8050b599b867

Control-plane actions (11)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Microsoft documents Automation account scope for managing one account. Broader scope also exposes the role's deployment, monitoring, support, and workspace-key operations across inherited resources.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (3)

Assignment guidance

Reserve Automation Contributor for trusted Automation platform administrators at the Automation account scope. Use Job Operator, Operator, and Runbook Operator for execution duties, and review runbook managed-identity access separately from user access to the Automation account.

Related roles (3)

Editorial sources (6)

Official Microsoft Learn documentation →