Azure Management and governance built-in role
Azure Connected Machine Onboarding
Onboards new servers as Azure Arc-enabled server resources. Microsoft documents it for onboarding credentials because it can read and create connected-machine resources but cannot delete registered servers or manage extensions after onboarding. It has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: b64e21ea-ac4e-4cdf-9dc9-5b892992bee7
Control-plane actions (11)
Microsoft.HybridCompute/machines/readMicrosoft.HybridCompute/machines/writeMicrosoft.HybridCompute/settings/readMicrosoft.HybridCompute/settings/writeMicrosoft.HybridCompute/gateways/readMicrosoft.HybridCompute/privateLinkScopes/readMicrosoft.GuestConfiguration/guestConfigurationAssignments/readMicrosoft.Insights/dataCollectionRuleAssociations/writeMicrosoft.Insights/dataCollectionRuleAssociations/deleteMicrosoft.Insights/dataCollectionRuleAssociations/readMicrosoft.HybridCompute/machines/addExtensions/action
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign to the onboarding service principal at only the resource groups or subscriptions where it may register servers. Resource-group scope limits where a compromised credential can create unauthorized Arc resources; parent assignments inherit to every child group.
Common use cases (2)
- Connect servers to Azure Arc at scale by using a dedicated service principal or another approved onboarding credential.
- Separate initial server registration from ongoing extension, run-command, license, and machine lifecycle administration.
Prerequisites (2)
- The operator needs local administrator access on each server and network connectivity required by the Connected Machine agent.
- Create and secure a dedicated Microsoft Entra service principal, preferably with certificate authentication for at-scale onboarding.
Best practices (2)
- Assign only to the onboarding service principal and scope each principal to the minimum resource groups owned by its deployment team.
- Prefer certificate authentication, rotate credentials, and remove the onboarding assignment when the enrollment campaign ends.
Security considerations (2)
- A stolen onboarding credential can register attacker-controlled servers into the allowed Azure scope.
- The role cannot delete existing servers or manage extensions, and it has no data-plane access, but the onboarding identity still requires protection and monitoring.
Assignment guidance
Assign Azure Connected Machine Onboarding to the dedicated onboarding service principal at the target resource group. Do not use broad Contributor or Resource Administrator merely to register servers, and remove or rotate the credential after use.
Related roles (1)
- Azure Connected Machine Resource Administrator: Microsoft documents this separate role for ongoing management after a server is connected.
Editorial sources (6)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Identity and authorization for Azure Arc-enabled servers →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Planning and deployment guidance for Azure Arc-enabled servers →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.