Azure Management and governance built-in role

Automation Job Operator

Creates and manages jobs for every runbook in an Automation account and can read job streams and output. Microsoft documents assignment at the Automation account scope; resource-group read access is also needed to start runbooks. It does not edit runbook definitions or other Automation assets.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 4fe576fe-1146-4730-92eb-48519fa6bf9f

Control-plane actions (13)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the Automation account. When paired with resource-group read access, the operator can start any runbook in that account; combine with Automation Runbook Operator at individual runbook scope when only selected runbooks should execute.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (3)

Assignment guidance

Assign at the Automation account to an operations group that may run every runbook. For selected-runbook execution, pair Job Operator at the account with Runbook Operator only on approved runbooks and keep target-resource access on the runbook identity.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →