Azure Compute built-in role
Classic Virtual Machine Contributor
Lets you manage classic virtual machines, but not access to them, and not the virtual network or storage account they're connected to.
Control-plane and data-plane permissions below are imported directly from Microsoft Learn. In-app editorial guidance (use cases, best practices, security notes) and least-privilege recommendations are still pending review.
Role definition ID: d73bb868-a0df-4d4d-bd69-98a00b01fccb
Control-plane actions (17)
Microsoft.Authorization/*/readMicrosoft.ClassicCompute/domainNames/*Microsoft.ClassicCompute/virtualMachines/*Microsoft.ClassicNetwork/networkSecurityGroups/join/actionMicrosoft.ClassicNetwork/reservedIps/link/actionMicrosoft.ClassicNetwork/reservedIps/readMicrosoft.ClassicNetwork/virtualNetworks/join/actionMicrosoft.ClassicNetwork/virtualNetworks/readMicrosoft.ClassicStorage/storageAccounts/disks/readMicrosoft.ClassicStorage/storageAccounts/images/readMicrosoft.ClassicStorage/storageAccounts/listKeys/actionMicrosoft.ClassicStorage/storageAccounts/readMicrosoft.Insights/alertRules/*Microsoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/