Azure Databases built-in role

Cosmos DB Operator

Broadly manages Azure Cosmos DB accounts through the Azure control plane while excluding account keys, connection strings, copy and data-transfer jobs, and writes or deletes for native data-plane role definitions and assignments. It has no DataActions and does not authorize item access.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 230815da-be43-4aae-9cb4-875f7bd000aa

Control-plane actions (8)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (30)

Assignable scopes (1)

Practical scope

Assign on an individual Cosmos DB account or a dedicated resource group containing accounts the operator owns. Parent-scope assignments are inherited. The role controls account resources but does not grant native Cosmos DB data-plane access or Azure RBAC role-assignment authority.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Cosmos DB Operator to the trusted account-operations identity at the individual account or dedicated resource-group scope. Keep native data roles and their administration separate, and use DocumentDB Account Contributor only when excluded key or account operations are explicitly required.

Related roles (2)

Editorial sources (4)

Official Microsoft Learn documentation →