Azure Compute built-in role

Azure Batch Job Submitter

Reads existing Batch applications, application-package versions, and pools, and creates and manages Batch jobs and job schedules through DataActions. It does not manage the Batch account, applications, or pools.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 48e5e92e-a480-4e71-aa9c-2778f4c13781

Control-plane actions (5)

Data-plane actions (2)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the Batch account containing the approved pools and applications. Parent-scope assignments are inherited by all contained Batch accounts. Job and schedule writes are Batch data-plane permissions; the supporting pool and application visibility is in the control plane.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (4)

Assignment guidance

Use Azure Batch Job Submitter for the job-running identity at the individual Batch account. Escalate to Data Contributor only when that identity must also create or change pools or application packages; do not use Account Contributor for routine submission.

Related roles (2)

Editorial sources (8)

Official Microsoft Learn documentation →