Azure Analytics built-in role

HDInsight Domain Services Contributor

Authorizes the user-assigned managed identity used by an HDInsight Enterprise Security Package cluster to read Microsoft Entra Domain Services and create, modify, or delete required organizational-unit operations. The role uses control-plane Actions and no DataActions. Enterprise Security Package support ends July 31, 2026.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 8d8d5a11-05d3-4bda-a417-a08778121c7c

Control-plane actions (3)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Microsoft directs administrators to assign this role to the user-assigned managed identity in Access control (IAM) on the Microsoft Entra Domain Services resource. A broader parent assignment is inherited by other resources below that scope and is not required by the documented ESP setup.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

For an existing ESP environment that still requires domain operations before support ends, assign HDInsight Domain Services Contributor to its user-assigned managed identity on the Microsoft Entra Domain Services resource. Grant Managed Identity Operator separately only to approved users or groups that must use the identity, then remove both access paths when migration or decommissioning is complete.

Related roles (1)

Common questions

When should I assign the HDInsight Domain Services Contributor Azure role?

Assign HDInsight Domain Services Contributor when you need to: Maintain the domain-services operations required by an existing ESP-enabled HDInsight cluster during its final supported migration or decommissioning period.; and Allow the cluster managed identity to create and delete the organizational units required by the documented ESP integration.. Practical scope: Microsoft directs administrators to assign this role to the user-assigned managed identity in Access control (IAM) on the Microsoft Entra Domain Services resource. A broader parent assignment is inherited by other resources below that scope and is not required by the documented ESP setup.

What permissions does the HDInsight Domain Services Contributor Azure role grant?

The role definition grants 3 combined control-plane and data-plane actions. Representative operations include: Microsoft.AAD/*/read; Microsoft.AAD/domainServices/*/read; and Microsoft.AAD/domainServices/oucontainer/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the HDInsight Domain Services Contributor Azure role?

Key considerations when assigning HDInsight Domain Services Contributor: The role permits the managed identity to create and delete organizational units used by ESP in Microsoft Entra Domain Services.; Users or groups with Managed Identity Operator on this managed identity can use it when creating ESP clusters, so that separate assignment controls who can exercise the identity.; and Enterprise Security Package is retiring and reaches end of support on July 31, 2026; retaining its access path after migration or decommissioning leaves unnecessary authorization in place.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →