Azure Compute built-in role

Compute Gallery Sharing Admin

Changes an Azure Compute Gallery sharing profile so images can be shared directly with subscriptions or tenants or exposed through a community gallery. The role grants the gallery share action only; it does not publish or edit image content.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 1ef6a3be-d0ac-425d-8c01-acb62866290b

Control-plane actions (1)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Microsoft documents assignment at the subscription or gallery level for enabling direct or community sharing. A gallery-level assignment confines authority to that gallery; a subscription assignment applies to galleries in the inherited scope. The role has one control-plane sharing Action and no DataActions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Grant at a specific gallery to a small publishing-governance group after audience, preview, legal, privacy, and image-security review. Keep artifact publishing separate, use normal RBAC sharing for named consumers, and reset wider sharing before deleting a shared gallery.

Related roles (1)

Editorial sources (8)

Official Microsoft Learn documentation →