Azure Management and governance built-in role
Azure Customer Lockbox Approver for Subscription
Approves or denies Microsoft support requests for time-bound access to specific Azure resources in a subscription, or to the subscription itself, when Customer Lockbox is enabled for the tenant. It does not itself grant ordinary resource management or data access.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 4dae6930-7baf-46f5-909e-0383bc931c46
Control-plane actions (6)
Microsoft.Resources/subscriptions/readMicrosoft.CustomerLockbox/requests/UpdateApproval/actionMicrosoft.CustomerLockbox/requests/readMicrosoft.Authorization/*/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Insights/eventtypes/values/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at the subscription containing the resources whose Lockbox requests the approver governs. The role is subscription-focused; do not treat an inherited broad assignment as approval authority that should automatically span unrelated subscriptions.
Common use cases (2)
- Review the justification, requested resource, duration, and support context for a Microsoft engineer access request.
- Approve or deny a Customer Lockbox request within the response window during an active support case.
Prerequisites (2)
- Customer Lockbox for Microsoft Azure must be enabled on the tenant where the subscription resides and the applicable support request must reach the customer-approval stage.
- Configure approver notification and a backup approval process so requests are reviewed before expiration.
Best practices (2)
- Assign to a small security or compliance group independent from ordinary support-request operators.
- Validate case identity, resource scope, requested duration, and business impact before approval, and retain the audit record.
Security considerations (2)
- Approval authorizes Microsoft support access to customer content or resources for the approved request and time window.
- Denial or delayed approval can prevent troubleshooting, while careless approval weakens the intended customer control.
Assignment guidance
Assign at each protected subscription to named security or compliance approvers. Keep support-case creation separate, maintain alternate notifications, and require review of the exact request before approval.
Editorial sources (5)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Customer Lockbox for Microsoft Azure →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.