Azure Management and governance built-in role

Hierarchy Settings Administrator

Reads, writes, and deletes management-group hierarchy settings, including settings that control whether subscription and management-group owners can create new management groups and which management group receives new subscriptions by default. It has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 350f8d15-c687-4448-8ae1-157740a3936d

Control-plane actions (2)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Hierarchy settings are configured at the tenant root management group and apply to the management-group hierarchy. This tenant-wide governance effect is different from assigning an ordinary resource role at a child subscription or resource group.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign only at the tenant root management group to the central hierarchy governance team. Require change review and verify inherited policy and RBAC consequences before modifying or deleting settings.

Related roles (1)

Common questions

When should I assign the Hierarchy Settings Administrator Azure role?

Assign Hierarchy Settings Administrator when you need to: Require management-group write permission at the root before users can create management groups.; and Set or change the default management group for newly added subscriptions.. Practical scope: Hierarchy settings are configured at the tenant root management group and apply to the management-group hierarchy. This tenant-wide governance effect is different from assigning an ordinary resource role at a child subscription or resource group.

What permissions does the Hierarchy Settings Administrator Azure role grant?

The role definition grants 2 combined control-plane and data-plane actions. Representative operations include: Microsoft.Management/managementGroups/settings/write; and Microsoft.Management/managementGroups/settings/delete. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Hierarchy Settings Administrator Azure role?

Key considerations when assigning Hierarchy Settings Administrator: A hierarchy-setting change can alter who may create management groups and where new subscriptions enter the governance hierarchy.; and Incorrect default placement can cause subscriptions to inherit unintended policy and role assignments or miss required controls.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →