Azure Identity built-in role

Domain Services Contributor

Creates and manages Microsoft Entra Domain Services managed domains and the related Azure networking, deployment, monitoring, and diagnostic configuration exposed by the built-in role.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: eeaeda52-9324-47f6-8069-5d5bade478b2

Control-plane actions (69)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The built-in definition is available throughout the Azure hierarchy, but effective access is limited to the selected assignment scope and inherited child scopes. Its Actions cover Domain Services and related control-plane resources such as virtual networks, subnets, network security groups, route tables, deployments, and diagnostics. It has no DataActions.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (4)

Assignment guidance

Assign Domain Services Contributor to the team that deploys or changes the managed domain and its related network configuration, at the narrowest scope containing those resources. Grant the separate Entra prerequisites only to the principals and for the duration required by the deployment workflow. Use Domain Services Reader for inspection-only work.

Related roles (3)

Editorial sources (3)

Official Microsoft Learn documentation →