Azure Management and governance built-in role
Blueprint Operator
Assigns existing published Azure Blueprint versions and manages blueprint assignments without creating blueprint definitions. Microsoft states that this built-in role works only when the blueprint assignment uses a user-assigned managed identity.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 437d2ced-4a38-4302-8479-ed2bcb43d090
Control-plane actions (5)
Microsoft.Authorization/*/readMicrosoft.Blueprint/blueprintAssignments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/deployments/*Microsoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at the target management group or subscription where published blueprints may be assigned. Assignment effects flow to resources within that target hierarchy, while the user-assigned managed identity receives the permissions needed to deploy assignment artifacts.
Common use cases (2)
- Create or update assignments of an approved published blueprint version to a management group or subscription.
- Operate existing blueprint assignment lifecycle while definition authoring remains with a separate governance team.
Prerequisites (2)
- A published blueprint version and a user-assigned managed identity for the assignment must already exist.
- The managed identity must receive the artifact deployment permissions required by the blueprint assignment.
Best practices (2)
- Assign only at approved target scopes and use versioned published definitions controlled by Blueprint Contributor.
- Review the user-assigned identity permissions and assignment lock behavior before deployment, and plan migration from the preview service.
Security considerations (2)
- A blueprint assignment can deploy resources, policies, role assignments, and locks through its managed identity across the target scope.
- The operator cannot author definitions, but choosing a version, parameters, target scope, and identity can materially change the environment.
Assignment guidance
Assign to the deployment-governance operator at the exact management group or subscription receiving existing published blueprints. Require a user-assigned managed identity, review its permissions separately, and keep authoring on Blueprint Contributor.
Related roles (2)
- Blueprint Contributor: Authors and publishes blueprint definitions while Operator assigns published versions.
- Managed Identity Operator: Relevant when a principal must attach the user-assigned managed identity required by the assignment workflow.
Editorial sources (6)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- What is Azure Blueprints (Preview)? →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Understand the lifecycle of an Azure Blueprint →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.