Azure Compute built-in role

Compute Gallery Sharing Admin

Changes an Azure Compute Gallery sharing profile so images can be shared directly with subscriptions or tenants or exposed through a community gallery. The role grants the gallery share action only; it does not publish or edit image content.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 1ef6a3be-d0ac-425d-8c01-acb62866290b

Control-plane actions (1)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Microsoft documents assignment at the subscription or gallery level for enabling direct or community sharing. A gallery-level assignment confines authority to that gallery; a subscription assignment applies to galleries in the inherited scope. The role has one control-plane sharing Action and no DataActions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Grant at a specific gallery to a small publishing-governance group after audience, preview, legal, privacy, and image-security review. Keep artifact publishing separate, use normal RBAC sharing for named consumers, and reset wider sharing before deleting a shared gallery.

Related roles (1)

Common questions

When should I assign the Compute Gallery Sharing Admin Azure role?

Assign Compute Gallery Sharing Admin when you need to: Authorize a controlled direct share of gallery images to selected subscriptions or tenants.; and Enable or reset community sharing after the organization approves public distribution of the gallery.. Practical scope: Microsoft documents assignment at the subscription or gallery level for enabling direct or community sharing. A gallery-level assignment confines authority to that gallery; a subscription assignment applies to galleries in the inherited scope. The role has one control-plane sharing Action and no DataActions.

What permissions does the Compute Gallery Sharing Admin Azure role grant?

The role definition grants 1 combined control-plane and data-plane actions. Representative operations include: Microsoft.Compute/galleries/share/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Compute Gallery Sharing Admin Azure role?

Key considerations when assigning Compute Gallery Sharing Admin: Direct sharing distributes images to all users in the selected subscriptions or tenants, while community sharing makes images visible to all Azure users.; Public publisher contact and image-definition metadata become visible, and Microsoft does not verify, scan, or support community images.; and Stopping public sharing can disrupt scale-out for consumers, and leaked intellectual property cannot be recalled from prior consumers.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (8)

Official Microsoft Learn documentation →