Azure Compute built-in role

Compute Gallery Artifacts Publisher

Publishes and manages Azure Compute Gallery artifacts, images, and supporting image resources. The built-in definition explicitly excludes the gallery share action, so publishing content does not by itself authorize direct, tenant-wide, subscription-wide, or public sharing.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 85a2d0d9-2eba-4c9c-b355-11c2cc0788ab

Control-plane actions (11)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (1)

Assignable scopes (1)

Practical scope

Assign at the gallery or its resource group when the publisher owns all contained definitions and versions; broader assignments are inherited by child galleries. Permissions are control-plane Actions only and include gallery, image, VM, disk, deployment, and alert operations, with no DataActions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign to the image publishing group or pipeline at the gallery or dedicated gallery resource group. Keep Compute Gallery Sharing Admin separate, validate artifacts before publication, and narrow access to the source resources used by the publishing process.

Related roles (1)

Editorial sources (6)

Official Microsoft Learn documentation →