Azure Compute built-in role

Compute Gallery Artifacts Publisher

Publishes and manages Azure Compute Gallery artifacts, images, and supporting image resources. The built-in definition explicitly excludes the gallery share action, so publishing content does not by itself authorize direct, tenant-wide, subscription-wide, or public sharing.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 85a2d0d9-2eba-4c9c-b355-11c2cc0788ab

Control-plane actions (11)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (1)

Assignable scopes (1)

Practical scope

Assign at the gallery or its resource group when the publisher owns all contained definitions and versions; broader assignments are inherited by child galleries. Permissions are control-plane Actions only and include gallery, image, VM, disk, deployment, and alert operations, with no DataActions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign to the image publishing group or pipeline at the gallery or dedicated gallery resource group. Keep Compute Gallery Sharing Admin separate, validate artifacts before publication, and narrow access to the source resources used by the publishing process.

Related roles (1)

Common questions

When should I assign the Compute Gallery Artifacts Publisher Azure role?

Assign Compute Gallery Artifacts Publisher when you need to: Build, version, replicate, and maintain approved VM images or applications in an Azure Compute Gallery.; and Operate an image-publishing pipeline without allowing that pipeline to change the gallery sharing profile.. Practical scope: Assign at the gallery or its resource group when the publisher owns all contained definitions and versions; broader assignments are inherited by child galleries. Permissions are control-plane Actions only and include gallery, image, VM, disk, deployment, and alert operations, with no DataActions.

What permissions does the Compute Gallery Artifacts Publisher Azure role grant?

The role definition grants 11 combined control-plane and data-plane actions. Representative operations include: Microsoft.Compute/galleries/*; Microsoft.Compute/locations/capsOperations/read; Microsoft.Compute/locations/communityGalleries/*; Microsoft.Compute/locations/sharedGalleries/*; Microsoft.Compute/images/*; and Microsoft.Compute/virtualMachines/write. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Compute Gallery Artifacts Publisher Azure role?

Key considerations when assigning Compute Gallery Artifacts Publisher: The role can create, change, and delete gallery artifacts and images that become the trusted source for future VMs.; A compromised publisher can distribute vulnerable software or secrets embedded in an image even though it cannot invoke gallery sharing.; and The definition can write VMs and disks and manage deployments, so it is broader than a simple image-version upload permission.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →