Azure Management and governance built-in role
Blueprint Contributor
Creates and manages Azure Blueprint definitions and artifacts and publishes blueprint versions, but does not assign them. Azure Blueprints remains marked Preview, and Microsoft directs new governance designs toward Template Specs and Deployment Stacks.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 41077137-e803-4205-871c-5a86e6a753b4
Control-plane actions (5)
Microsoft.Authorization/*/readMicrosoft.Blueprint/blueprints/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/deployments/*Microsoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Blueprint definitions live at a management-group or subscription scope and are inherited by child scopes. Assign the role where definitions are authored; a management-group assignment exposes governance artifacts across the hierarchy beneath it.
Common use cases (2)
- Maintain an existing Azure Blueprints definition and artifact lifecycle, including draft changes and published versions.
- Separate blueprint authorship and publishing from assignment operations in a retained Blueprints deployment.
Prerequisites (2)
- Use only for an existing Blueprints implementation after reviewing Microsoft's migration direction to Template Specs and Deployment Stacks.
- Identify the definition scope, artifacts, versioning process, and approver responsible for publishing changes.
Best practices (2)
- Keep authoring and assignment duties separate and treat published versions as immutable governance releases.
- Plan migration rather than expanding a preview Blueprints dependency for new governance designs.
Security considerations (2)
- Changing or publishing a definition changes the governance package available for later assignment across inherited scopes.
- The role cannot assign a blueprint, but malicious or defective artifacts can be deployed by a separate operator.
Assignment guidance
Assign at the existing blueprint definition scope to the governance authors who maintain and publish versions. Keep assignment authority on Blueprint Operator and plan the supported successor architecture.
Related roles (2)
- Blueprint Operator: Assigns existing published blueprint versions but cannot create definitions.
- Template Spec Contributor: Microsoft identifies Template Specs, with Deployment Stacks, as part of the successor path for blueprint-style governance assets.
Editorial sources (6)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- What is Azure Blueprints (Preview)? →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Understand the lifecycle of an Azure Blueprint →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.