Azure Identity built-in role
Domain Services Contributor
Creates and manages Microsoft Entra Domain Services managed domains and the related Azure networking, deployment, monitoring, and diagnostic configuration exposed by the built-in role.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: eeaeda52-9324-47f6-8069-5d5bade478b2
Control-plane actions (69)
Microsoft.Authorization/*/readMicrosoft.Resources/deployments/readMicrosoft.Resources/deployments/writeMicrosoft.Resources/deployments/deleteMicrosoft.Resources/deployments/cancel/actionMicrosoft.Resources/deployments/validate/actionMicrosoft.Resources/deployments/whatIf/actionMicrosoft.Resources/deployments/exportTemplate/actionMicrosoft.Resources/deployments/operations/readMicrosoft.Resources/deployments/operationstatuses/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Insights/AlertRules/WriteMicrosoft.Insights/AlertRules/DeleteMicrosoft.Insights/AlertRules/ReadMicrosoft.Insights/AlertRules/Activated/ActionMicrosoft.Insights/AlertRules/Resolved/ActionMicrosoft.Insights/AlertRules/Throttled/ActionMicrosoft.Insights/AlertRules/Incidents/ReadMicrosoft.Insights/Logs/ReadMicrosoft.Insights/Metrics/ReadMicrosoft.Insights/DiagnosticSettings/*Microsoft.Insights/DiagnosticSettingsCategories/ReadMicrosoft.AAD/register/actionMicrosoft.AAD/unregister/actionMicrosoft.AAD/domainServices/*Microsoft.Network/register/actionMicrosoft.Network/unregister/actionMicrosoft.Network/virtualNetworks/readMicrosoft.Network/virtualNetworks/writeMicrosoft.Network/virtualNetworks/deleteMicrosoft.Network/virtualNetworks/peer/actionMicrosoft.Network/virtualNetworks/join/actionMicrosoft.Network/virtualNetworks/subnets/readMicrosoft.Network/virtualNetworks/subnets/writeMicrosoft.Network/virtualNetworks/subnets/deleteMicrosoft.Network/virtualNetworks/subnets/join/actionMicrosoft.Network/virtualNetworks/virtualNetworkPeerings/readMicrosoft.Network/virtualNetworks/virtualNetworkPeerings/writeMicrosoft.Network/virtualNetworks/virtualNetworkPeerings/deleteMicrosoft.Network/virtualNetworks/providers/Microsoft.Insights/diagnosticSettings/readMicrosoft.Network/virtualNetworks/providers/Microsoft.Insights/metricDefinitions/readMicrosoft.Network/azureFirewalls/readMicrosoft.Network/ddosProtectionPlans/readMicrosoft.Network/ddosProtectionPlans/join/actionMicrosoft.Network/loadBalancers/readMicrosoft.Network/loadBalancers/deleteMicrosoft.Network/loadBalancers/*/readMicrosoft.Network/loadBalancers/backendAddressPools/join/actionMicrosoft.Network/loadBalancers/inboundNatRules/join/actionMicrosoft.Network/natGateways/join/actionMicrosoft.Network/networkInterfaces/readMicrosoft.Network/networkInterfaces/writeMicrosoft.Network/networkInterfaces/deleteMicrosoft.Network/networkInterfaces/join/actionMicrosoft.Network/networkSecurityGroups/defaultSecurityRules/readMicrosoft.Network/networkSecurityGroups/readMicrosoft.Network/networkSecurityGroups/writeMicrosoft.Network/networkSecurityGroups/deleteMicrosoft.Network/networkSecurityGroups/join/actionMicrosoft.Network/networkSecurityGroups/securityRules/readMicrosoft.Network/networkSecurityGroups/securityRules/writeMicrosoft.Network/networkSecurityGroups/securityRules/deleteMicrosoft.Network/routeTables/readMicrosoft.Network/routeTables/writeMicrosoft.Network/routeTables/deleteMicrosoft.Network/routeTables/join/actionMicrosoft.Network/routeTables/routes/readMicrosoft.Network/routeTables/routes/writeMicrosoft.Network/routeTables/routes/delete
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The built-in definition is available throughout the Azure hierarchy, but effective access is limited to the selected assignment scope and inherited child scopes. Its Actions cover Domain Services and related control-plane resources such as virtual networks, subnets, network security groups, route tables, deployments, and diagnostics. It has no DataActions.
Common use cases (2)
- Create a Microsoft Entra Domain Services managed domain and its required Azure resources.
- Maintain the managed domain and related virtual-network, DNS, monitoring, and diagnostic configuration within an approved scope.
Prerequisites (3)
- An active Azure subscription and an associated Microsoft Entra tenant are required for managed-domain deployment.
- Microsoft documents separate Application Administrator and Groups Administrator Microsoft Entra roles as prerequisites to enable Domain Services.
- Prepare a virtual network whose DNS servers can resolve required infrastructure before deployment.
Best practices (3)
- Choose the subscription, resource group, region, DNS name, and virtual network carefully because a managed domain cannot be moved after creation.
- Use private IP address space for the Domain Services virtual network and avoid DNS namespace conflicts.
- Keep this Azure role at the resource group or other narrow scope containing the managed domain and its approved network dependencies.
Security considerations (4)
- The role can change or delete Domain Services and a substantial set of related network resources in scope.
- The separate Microsoft Entra roles required for deployment administer directory objects; this Azure role does not replace or include them.
- Domain Services creates required enterprise applications in Microsoft Entra ID; Microsoft warns not to delete them.
- The role has no DataActions, but its control-plane network and managed-domain authority remains sensitive.
Assignment guidance
Assign Domain Services Contributor to the team that deploys or changes the managed domain and its related network configuration, at the narrowest scope containing those resources. Grant the separate Entra prerequisites only to the principals and for the duration required by the deployment workflow. Use Domain Services Reader for inspection-only work.
Related roles (3)
- Domain Services Reader: Read-only Azure alternative for the managed domain and related network configuration.
- Application Administrator: Separate Microsoft Entra role documented as a prerequisite to enable Domain Services; it is not included in this Azure role.
- Groups Administrator: Separate Microsoft Entra role documented as a prerequisite to enable Domain Services; it is not included in this Azure role.
Editorial sources (3)
- Azure built-in roles for Identity →
Supports: Description, Practical scope, Common use cases, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Create and configure a Microsoft Entra Domain Services managed domain →
Supports: Description, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.