Azure Management and governance built-in role

Hierarchy Settings Administrator

Reads, writes, and deletes management-group hierarchy settings, including settings that control whether subscription and management-group owners can create new management groups and which management group receives new subscriptions by default. It has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 350f8d15-c687-4448-8ae1-157740a3936d

Control-plane actions (2)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Hierarchy settings are configured at the tenant root management group and apply to the management-group hierarchy. This tenant-wide governance effect is different from assigning an ordinary resource role at a child subscription or resource group.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign only at the tenant root management group to the central hierarchy governance team. Require change review and verify inherited policy and RBAC consequences before modifying or deleting settings.

Related roles (1)

Editorial sources (6)

Official Microsoft Learn documentation →