Azure Compute built-in role
Compute Gallery Sharing Admin
Changes an Azure Compute Gallery sharing profile so images can be shared directly with subscriptions or tenants or exposed through a community gallery. The role grants the gallery share action only; it does not publish or edit image content.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 1ef6a3be-d0ac-425d-8c01-acb62866290b
Control-plane actions (1)
Microsoft.Compute/galleries/share/action
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Microsoft documents assignment at the subscription or gallery level for enabling direct or community sharing. A gallery-level assignment confines authority to that gallery; a subscription assignment applies to galleries in the inherited scope. The role has one control-plane sharing Action and no DataActions.
Common use cases (2)
- Authorize a controlled direct share of gallery images to selected subscriptions or tenants.
- Enable or reset community sharing after the organization approves public distribution of the gallery.
Prerequisites (2)
- Use a gallery created with the sharing mode required by the direct-sharing or community-sharing workflow; existing private galleries cannot always be converted.
- Review feature availability, preview registration, regional and encryption limitations, target subscriptions or tenants, and the public publisher metadata before sharing.
Best practices (3)
- Assign at the individual gallery rather than the subscription unless one administrator must control sharing for every gallery.
- Prefer ordinary Azure RBAC sharing for named users, groups, or service principals; use direct or community sharing only for the documented wider audience.
- Generalize and scan images, remove secrets and machine-specific data, and complete legal and intellectual-property review before public sharing.
Security considerations (3)
- Direct sharing distributes images to all users in the selected subscriptions or tenants, while community sharing makes images visible to all Azure users.
- Public publisher contact and image-definition metadata become visible, and Microsoft does not verify, scan, or support community images.
- Stopping public sharing can disrupt scale-out for consumers, and leaked intellectual property cannot be recalled from prior consumers.
Assignment guidance
Grant at a specific gallery to a small publishing-governance group after audience, preview, legal, privacy, and image-security review. Keep artifact publishing separate, use normal RBAC sharing for named consumers, and reset wider sharing before deleting a shared gallery.
Related roles (1)
- Owner: Microsoft documents subscription Owner as the other identity that can enable direct or community gallery sharing; Sharing Admin provides the dedicated sharing action without broad ownership.
Editorial sources (8)
- Azure built-in roles for Compute →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Overview of Azure Compute Gallery →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Share resources in Azure Compute Gallery →
Supports: Best practices. Retrieved 2026-07-16.
- Share Azure Compute Gallery resources directly with subscriptions and tenants →
Supports: Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Share Azure Compute Gallery resources with a community gallery →
Supports: Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.