Azure Management and governance built-in role

Azure Customer Lockbox Approver for Subscription

Approves or denies Microsoft support requests for time-bound access to specific Azure resources in a subscription, or to the subscription itself, when Customer Lockbox is enabled for the tenant. It does not itself grant ordinary resource management or data access.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 4dae6930-7baf-46f5-909e-0383bc931c46

Control-plane actions (6)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the subscription containing the resources whose Lockbox requests the approver governs. The role is subscription-focused; do not treat an inherited broad assignment as approval authority that should automatically span unrelated subscriptions.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign at each protected subscription to named security or compliance approvers. Keep support-case creation separate, maintain alternate notifications, and require review of the exact request before approval.

Common questions

When should I assign the Azure Customer Lockbox Approver for Subscription Azure role?

Assign Azure Customer Lockbox Approver for Subscription when you need to: Review the justification, requested resource, duration, and support context for a Microsoft engineer access request.; and Approve or deny a Customer Lockbox request within the response window during an active support case.. Practical scope: Assign at the subscription containing the resources whose Lockbox requests the approver governs. The role is subscription-focused; do not treat an inherited broad assignment as approval authority that should automatically span unrelated subscriptions.

What permissions does the Azure Customer Lockbox Approver for Subscription Azure role grant?

The role definition grants 6 combined control-plane and data-plane actions. Representative operations include: Microsoft.Resources/subscriptions/read; Microsoft.CustomerLockbox/requests/UpdateApproval/action; Microsoft.CustomerLockbox/requests/read; Microsoft.Authorization/*/read; Microsoft.Resources/subscriptions/resourceGroups/read; and Microsoft.Insights/eventtypes/values/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure Customer Lockbox Approver for Subscription Azure role?

Key considerations when assigning Azure Customer Lockbox Approver for Subscription: Approval authorizes Microsoft support access to customer content or resources for the approved request and time window.; and Denial or delayed approval can prevent troubleshooting, while careless approval weakens the intended customer control.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →