Azure Management and governance built-in role

Azure Customer Lockbox Approver for Subscription

Approves or denies Microsoft support requests for time-bound access to specific Azure resources in a subscription, or to the subscription itself, when Customer Lockbox is enabled for the tenant. It does not itself grant ordinary resource management or data access.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 4dae6930-7baf-46f5-909e-0383bc931c46

Control-plane actions (6)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the subscription containing the resources whose Lockbox requests the approver governs. The role is subscription-focused; do not treat an inherited broad assignment as approval authority that should automatically span unrelated subscriptions.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign at each protected subscription to named security or compliance approvers. Keep support-case creation separate, maintain alternate notifications, and require review of the exact request before approval.

Editorial sources (5)

Official Microsoft Learn documentation →