Azure Compute built-in role

Data Operator for Managed Disks

Uploads VHD data only to empty managed disks and reads or exports data from detached managed disks and snapshots. Microsoft Learn explicitly does not support uploading a VHD to an empty snapshot. In the secured workflow, the SAS URI identifies the transfer endpoint and Microsoft Entra ID authorizes the requesting identity.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 959f8984-c045-4866-89c7-12bf9737be2e

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (4)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the specific disk or snapshot whenever possible; resource-group or broader assignments are inherited by every contained disk and snapshot. The role grants only data-plane upload and download operations, so a separate control-plane role is required to inspect resources or initiate the surrounding workflow.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Grant Data Operator for Managed Disks temporarily on the individual empty disk being uploaded or the individual disk or snapshot being exported. Have a separately authorized resource operator configure Microsoft Entra data-access mode and issue or revoke the SAS, then revoke both the SAS and this data role after validation.

Editorial sources (6)

Official Microsoft Learn documentation →