Azure Analytics built-in role
HDInsight on AKS Cluster Admin
Was the HDInsight on AKS control-plane role for creating, deleting, resizing, upgrading, monitoring, and managing clusters and their jobs within a cluster pool. The definition has control-plane Actions and no DataActions. HDInsight on AKS retired on January 31, 2025, so this role is retained only as legacy access metadata.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: fd036e6b-1266-47a0-b0bb-a05d04831731
Control-plane actions (35)
Microsoft.Authorization/*/readMicrosoft.HDInsight/clusterPools/clusters/readMicrosoft.HDInsight/clusterPools/clusters/writeMicrosoft.HDInsight/clusterPools/clusters/deleteMicrosoft.HDInsight/clusterPools/clusters/resize/actionMicrosoft.HDInsight/clusterpools/clusters/instanceviews/readMicrosoft.HDInsight/clusterPools/clusters/jobs/readMicrosoft.HDInsight/clusterPools/clusters/runjob/actionMicrosoft.HDInsight/clusterpools/clusters/serviceconfigs/readMicrosoft.HDInsight/clusterPools/clusters/availableupgrades/readMicrosoft.HDInsight/clusterPools/clusters/upgrade/actionMicrosoft.HDInsight/clusterPools/clusters/rollback/actionMicrosoft.HDInsight/clusterPools/clusters/upgradehistories/readMicrosoft.HDInsight/clusterPools/clusters/libraries/readMicrosoft.HDInsight/clusterPools/clusters/managelibraries/actionMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/deployments/operations/readMicrosoft.Resources/deployments/*/readMicrosoft.Resources/deployments/readMicrosoft.Resources/deployments/validate/actionMicrosoft.Resources/deployments/writeMicrosoft.Resources/deployments/exportTemplate/actionMicrosoft.Resources/subscriptions/resourcegroups/deployments/operations/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/subscriptions/operationresults/readMicrosoft.Insights/AlertRules/WriteMicrosoft.Insights/AlertRules/DeleteMicrosoft.Insights/AlertRules/ReadMicrosoft.Insights/AlertRules/Activated/ActionMicrosoft.Insights/AlertRules/Resolved/ActionMicrosoft.Insights/AlertRules/Throttled/ActionMicrosoft.Insights/AlertRules/Incidents/ReadMicrosoft.Insights/metrics/readMicrosoft.Insights/logs/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The archived authorization guidance applied this role to an HDInsight on AKS cluster through Access control (IAM). Any assignment made at a parent scope is inherited; stale inherited access must be removed at the scope where the assignment was originally created.
Common use cases (2)
- Inventory and remove stale HDInsight on AKS Cluster Admin assignments while retired-service references are cleaned up.
- Use the archived permission boundary to identify principals and automation that formerly managed clusters before migrating workload ownership to Microsoft Fabric or an equivalent Azure product.
Prerequisites (2)
- A cleanup owner must identify the retired HDInsight on AKS cluster assignment or inherited parent assignment and the principal that received it.
- The administrator removing the assignment needs Microsoft.Authorization/roleAssignments/delete at the scope where it was created.
Best practices (3)
- Do not create new HDInsight on AKS Cluster Admin assignments because the service retired on January 31, 2025.
- Migrate workload ownership to Microsoft Fabric or an equivalent Azure product and select roles for the replacement service independently.
- Remove stale direct and inherited assignments at their originating scopes after the retired-service cleanup is verified.
Security considerations (3)
- The legacy role definition includes cluster create, update, delete, resize, job execution, library management, deployment, monitoring, and log-reading authority.
- A parent-scope assignment can retain this broad legacy authority across multiple child resources even though HDInsight on AKS is retired.
- The role did not by itself grant the separate HDInsight on AKS cluster data-plane access configured through the authorization profile.
Assignment guidance
Do not make a new assignment. Locate each existing HDInsight on AKS Cluster Admin assignment in Access control (IAM) at the cluster or originating parent scope, confirm that retired-service migration or cleanup no longer depends on it, and remove it there. Inherited assignments cannot be removed from a child scope.
Related roles (1)
- HDInsight on AKS Cluster Pool Admin: The archived authorization table documents Cluster Pool Admin for cluster-pool management and Cluster Admin for management of an individual cluster within the pool.
Editorial sources (7)
- Azure built-in roles for Analytics →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Remove Azure role assignments →
Supports: Practical scope, Common use cases, Prerequisites, Best practices, Assignment guidance. Retrieved 2026-07-17.
- What is Azure HDInsight on AKS? (Preview) →
Supports: Description, Common use cases, Prerequisites, Best practices, Assignment guidance. Retrieved 2026-07-17.
- Manage cluster access →
Supports: Description, Practical scope, Common use cases, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.