Azure Storage built-in role

Avere Contributor

Creates and manages the compute, network, deployment, storage, monitoring, and support resources used by an Avere vFXT cluster. The role also has direct read, write, and delete access to blob data for the cluster workflow; the Avere documentation is archived, but the built-in role remains in the canonical Azure role inventory.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 4f8fab4f-1852-4a58-a46a-8eaf358af14a

Control-plane actions (20)

Data-plane actions (3)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role is assignable throughout the Azure hierarchy, but the Avere deployment guidance places the cluster controller, nodes, network, and storage in a deliberately isolated subscription or resource group. Its Actions are broad across those cluster resources and its DataActions reach blob contents, so the assignment scope controls both management-plane and data-plane exposure.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

For a maintained Avere vFXT environment, assign Avere Contributor to the documented cluster controller identity at the isolated deployment scope. Keep Avere Operator on cluster node identities, verify the controller and nodes do not share a scope with unrelated workloads, and remove assignments when the retired deployment is dismantled.

Related roles (1)

Common questions

When should I assign the Avere Contributor Azure role?

Assign Avere Contributor when you need to: Assign to the Avere vFXT cluster controller identity that creates and configures cluster nodes and their supporting Azure resources.; and Operate an existing archived Avere vFXT deployment whose controller still needs to add, change, or remove cluster infrastructure.. Practical scope: The role is assignable throughout the Azure hierarchy, but the Avere deployment guidance places the cluster controller, nodes, network, and storage in a deliberately isolated subscription or resource group. Its Actions are broad across those cluster resources and its DataActions reach blob contents, so the assignment scope controls both management-plane and data-plane exposure.

What permissions does the Avere Contributor Azure role grant?

The role definition grants 23 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Compute/*/read; Microsoft.Compute/availabilitySets/*; Microsoft.Compute/proximityPlacementGroups/*; Microsoft.Compute/virtualMachines/*; and Microsoft.Compute/disks/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Avere Contributor Azure role?

Key considerations when assigning Avere Contributor: The role can create, change, and delete virtual machines, disks, network interfaces, storage accounts, and blob data in scope.; A broad scope exposes unrelated infrastructure and stored data to the cluster controller identity.; and The archived service boundary should be preserved; this role is not a general-purpose compute or storage administrator role.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →