Azure Analytics built-in role

HDInsight on AKS Cluster Pool Admin

Was the HDInsight on AKS control-plane role for creating, updating, upgrading, and deleting cluster pools and creating clusters in those pools. The definition has control-plane Actions and no DataActions. HDInsight on AKS retired on January 31, 2025, so this role is retained only as legacy access metadata.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 7656b436-37d4-490a-a4ab-d39f838f0042

Control-plane actions (30)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The archived authorization guidance applied this role to an HDInsight on AKS cluster pool through Access control (IAM). Any assignment made at a parent scope is inherited; stale inherited access must be removed at the scope where the assignment was originally created.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Do not make a new assignment. Locate each existing HDInsight on AKS Cluster Pool Admin assignment in Access control (IAM) at the pool or originating parent scope, confirm that retired-service migration or cleanup no longer depends on it, and remove it there. Inherited assignments cannot be removed from a child scope.

Related roles (1)

Editorial sources (7)

Official Microsoft Learn documentation →