Azure Management and governance built-in role

Automation Operator

Views runbook names and properties and starts, stops, suspends, resumes, and schedules jobs for all runbooks in an Automation account without reading or modifying runbook definitions and other protected Automation assets.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: d3881f73-407a-4167-8283-e981cbba0404

Control-plane actions (21)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the Automation account when the operator may execute every runbook. Microsoft advises using Automation Job Operator plus Automation Runbook Operator instead when access must be limited to individual runbooks.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Automation Operator at the account only to operators authorized to run all contained runbooks. Use the scoped two-role pattern for selected runbooks and keep management duties on Automation Contributor.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →