Azure Management and governance built-in role

Essential Machine Management Administrator

Enables and manages Essential machine management preview enrollment for subscriptions, including ManagedOps, monitoring resources, data collection rules, deployments, policy-related configuration, and Log Analytics workspace shared-key retrieval. It is a broad control-plane role with no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 34013b0a-565b-43aa-8755-1b7c286f6cf7

Control-plane actions (19)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Microsoft requires the role on the subscription being enabled and, when monitoring workspaces are in another subscription, on the resource groups containing those workspaces. Parent assignments inherit and can expose workspace keys and management configuration beyond one enrollment.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign to the subscription enrollment administrator and, only where required, on external workspace resource groups. Add Managed Identity Operator and Resource Policy Contributor as documented, review the preview impact, and remove standing access when enrollment changes are complete.

Related roles (2)

Common questions

When should I assign the Essential Machine Management Administrator Azure role?

Assign Essential Machine Management Administrator when you need to: Enable or disable preview Essential machine management for a subscription so Azure VMs and Arc-enabled servers receive curated monitoring, security, and management configuration.; and Select and manage the Log Analytics workspace, Azure Monitor workspace, and user-assigned identity used by subscription enrollment.. Practical scope: Microsoft requires the role on the subscription being enabled and, when monitoring workspaces are in another subscription, on the resource groups containing those workspaces. Parent assignments inherit and can expose workspace keys and management configuration beyond one enrollment.

What permissions does the Essential Machine Management Administrator Azure role grant?

The role definition grants 19 combined control-plane and data-plane actions. Representative operations include: Microsoft.Resources/deployments/*; Microsoft.Insights/dataCollectionRules/read; Microsoft.Insights/dataCollectionRules/write; Microsoft.Monitor/accounts/write; Microsoft.Monitor/accounts/read; and Microsoft.ManagedOps/managedOps/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Essential Machine Management Administrator Azure role?

Key considerations when assigning Essential Machine Management Administrator: The role can retrieve Log Analytics workspace shared keys and change monitoring, data collection, deployments, policy-related configuration, and ManagedOps enrollment.; and Enabling or disabling enrollment affects every Azure VM and Arc-enabled server in the subscription and can change data collection or security posture.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →