Azure Management and governance built-in role

Blueprint Contributor

Creates and manages Azure Blueprint definitions and artifacts and publishes blueprint versions, but does not assign them. Azure Blueprints remains marked Preview, and Microsoft directs new governance designs toward Template Specs and Deployment Stacks.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 41077137-e803-4205-871c-5a86e6a753b4

Control-plane actions (5)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Blueprint definitions live at a management-group or subscription scope and are inherited by child scopes. Assign the role where definitions are authored; a management-group assignment exposes governance artifacts across the hierarchy beneath it.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign at the existing blueprint definition scope to the governance authors who maintain and publish versions. Keep assignment authority on Blueprint Operator and plan the supported successor architecture.

Related roles (2)

Common questions

When should I assign the Blueprint Contributor Azure role?

Assign Blueprint Contributor when you need to: Maintain an existing Azure Blueprints definition and artifact lifecycle, including draft changes and published versions.; and Separate blueprint authorship and publishing from assignment operations in a retained Blueprints deployment.. Practical scope: Blueprint definitions live at a management-group or subscription scope and are inherited by child scopes. Assign the role where definitions are authored; a management-group assignment exposes governance artifacts across the hierarchy beneath it.

What permissions does the Blueprint Contributor Azure role grant?

The role definition grants 5 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Blueprint/blueprints/*; Microsoft.Resources/subscriptions/resourceGroups/read; Microsoft.Resources/deployments/*; and Microsoft.Support/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Blueprint Contributor Azure role?

Key considerations when assigning Blueprint Contributor: Changing or publishing a definition changes the governance package available for later assignment across inherited scopes.; and The role cannot assign a blueprint, but malicious or defective artifacts can be deployed by a separate operator.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →