Azure Analytics built-in role

HDInsight on AKS Cluster Admin

Was the HDInsight on AKS control-plane role for creating, deleting, resizing, upgrading, monitoring, and managing clusters and their jobs within a cluster pool. The definition has control-plane Actions and no DataActions. HDInsight on AKS retired on January 31, 2025, so this role is retained only as legacy access metadata.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: fd036e6b-1266-47a0-b0bb-a05d04831731

Control-plane actions (35)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The archived authorization guidance applied this role to an HDInsight on AKS cluster through Access control (IAM). Any assignment made at a parent scope is inherited; stale inherited access must be removed at the scope where the assignment was originally created.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Do not make a new assignment. Locate each existing HDInsight on AKS Cluster Admin assignment in Access control (IAM) at the cluster or originating parent scope, confirm that retired-service migration or cleanup no longer depends on it, and remove it there. Inherited assignments cannot be removed from a child scope.

Related roles (1)

Editorial sources (7)

Official Microsoft Learn documentation →