Azure Management and governance built-in role

Automation Runbook Operator

Reads the name and properties of an individual Automation runbook so that, when combined with Automation Job Operator at the account, the assignee can create jobs for that selected runbook. It does not edit the runbook or independently provide complete job execution access.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 5fb5aef8-1081-4b8e-bb16-9d5d0385bab5

Control-plane actions (6)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on each approved runbook and pair it with Automation Job Operator at the containing Automation account. The two scopes deliberately separate account-level job operations from the set of runbooks the principal can select.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign on each approved runbook and pair with Automation Job Operator at the account. Do not replace the pair with Automation Operator unless execution of every runbook is intended.

Related roles (1)

Editorial sources (6)

Official Microsoft Learn documentation →