Azure Identity built-in role

Domain Services Contributor

Creates and manages Microsoft Entra Domain Services managed domains and the related Azure networking, deployment, monitoring, and diagnostic configuration exposed by the built-in role.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: eeaeda52-9324-47f6-8069-5d5bade478b2

Control-plane actions (69)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The built-in definition is available throughout the Azure hierarchy, but effective access is limited to the selected assignment scope and inherited child scopes. Its Actions cover Domain Services and related control-plane resources such as virtual networks, subnets, network security groups, route tables, deployments, and diagnostics. It has no DataActions.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (4)

Assignment guidance

Assign Domain Services Contributor to the team that deploys or changes the managed domain and its related network configuration, at the narrowest scope containing those resources. Grant the separate Entra prerequisites only to the principals and for the duration required by the deployment workflow. Use Domain Services Reader for inspection-only work.

Related roles (3)

Common questions

When should I assign the Domain Services Contributor Azure role?

Assign Domain Services Contributor when you need to: Create a Microsoft Entra Domain Services managed domain and its required Azure resources.; and Maintain the managed domain and related virtual-network, DNS, monitoring, and diagnostic configuration within an approved scope.. Practical scope: The built-in definition is available throughout the Azure hierarchy, but effective access is limited to the selected assignment scope and inherited child scopes. Its Actions cover Domain Services and related control-plane resources such as virtual networks, subnets, network security groups, route tables, deployments, and diagnostics. It has no DataActions.

What permissions does the Domain Services Contributor Azure role grant?

The role definition grants 69 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Resources/deployments/read; Microsoft.Resources/deployments/write; Microsoft.Resources/deployments/delete; Microsoft.Resources/deployments/cancel/action; and Microsoft.Resources/deployments/validate/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Domain Services Contributor Azure role?

Key considerations when assigning Domain Services Contributor: The role can change or delete Domain Services and a substantial set of related network resources in scope.; The separate Microsoft Entra roles required for deployment administer directory objects; this Azure role does not replace or include them.; Domain Services creates required enterprise applications in Microsoft Entra ID; Microsoft warns not to delete them.; and The role has no DataActions, but its control-plane network and managed-domain authority remains sensitive.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (3)

Official Microsoft Learn documentation →