Azure Management and governance built-in role
Hierarchy Settings Administrator
Reads, writes, and deletes management-group hierarchy settings, including settings that control whether subscription and management-group owners can create new management groups and which management group receives new subscriptions by default. It has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 350f8d15-c687-4448-8ae1-157740a3936d
Control-plane actions (2)
Microsoft.Management/managementGroups/settings/writeMicrosoft.Management/managementGroups/settings/delete
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Hierarchy settings are configured at the tenant root management group and apply to the management-group hierarchy. This tenant-wide governance effect is different from assigning an ordinary resource role at a child subscription or resource group.
Common use cases (2)
- Require management-group write permission at the root before users can create management groups.
- Set or change the default management group for newly added subscriptions.
Prerequisites (2)
- The tenant root management group must be initialized and the administrator must be authorized at that root scope.
- Review the downstream subscription-placement and management-group creation process before changing hierarchy settings.
Best practices (2)
- Limit the role to a small tenant governance team and use eligible access for changes.
- Protect the hierarchy, document the default management group, and audit every setting change.
Security considerations (2)
- A hierarchy-setting change can alter who may create management groups and where new subscriptions enter the governance hierarchy.
- Incorrect default placement can cause subscriptions to inherit unintended policy and role assignments or miss required controls.
Assignment guidance
Assign only at the tenant root management group to the central hierarchy governance team. Require change review and verify inherited policy and RBAC consequences before modifying or deleting settings.
Related roles (1)
- Management Group Contributor: Manages management-group lifecycle and subscription placement but does not replace hierarchy-settings authority.
Editorial sources (6)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- What are Azure management groups? →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Protect your resource hierarchy →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.