Azure Analytics built-in role

HDInsight on AKS Cluster Admin

Was the HDInsight on AKS control-plane role for creating, deleting, resizing, upgrading, monitoring, and managing clusters and their jobs within a cluster pool. The definition has control-plane Actions and no DataActions. HDInsight on AKS retired on January 31, 2025, so this role is retained only as legacy access metadata.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: fd036e6b-1266-47a0-b0bb-a05d04831731

Control-plane actions (35)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The archived authorization guidance applied this role to an HDInsight on AKS cluster through Access control (IAM). Any assignment made at a parent scope is inherited; stale inherited access must be removed at the scope where the assignment was originally created.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Do not make a new assignment. Locate each existing HDInsight on AKS Cluster Admin assignment in Access control (IAM) at the cluster or originating parent scope, confirm that retired-service migration or cleanup no longer depends on it, and remove it there. Inherited assignments cannot be removed from a child scope.

Related roles (1)

Common questions

When should I assign the HDInsight on AKS Cluster Admin Azure role?

Assign HDInsight on AKS Cluster Admin when you need to: Inventory and remove stale HDInsight on AKS Cluster Admin assignments while retired-service references are cleaned up.; and Use the archived permission boundary to identify principals and automation that formerly managed clusters before migrating workload ownership to Microsoft Fabric or an equivalent Azure product.. Practical scope: The archived authorization guidance applied this role to an HDInsight on AKS cluster through Access control (IAM). Any assignment made at a parent scope is inherited; stale inherited access must be removed at the scope where the assignment was originally created.

What permissions does the HDInsight on AKS Cluster Admin Azure role grant?

The role definition grants 35 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.HDInsight/clusterPools/clusters/read; Microsoft.HDInsight/clusterPools/clusters/write; Microsoft.HDInsight/clusterPools/clusters/delete; Microsoft.HDInsight/clusterPools/clusters/resize/action; and Microsoft.HDInsight/clusterpools/clusters/instanceviews/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the HDInsight on AKS Cluster Admin Azure role?

Key considerations when assigning HDInsight on AKS Cluster Admin: The legacy role definition includes cluster create, update, delete, resize, job execution, library management, deployment, monitoring, and log-reading authority.; A parent-scope assignment can retain this broad legacy authority across multiple child resources even though HDInsight on AKS is retired.; and The role did not by itself grant the separate HDInsight on AKS cluster data-plane access configured through the authorization profile.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →