Azure Containers built-in role

Kubernetes Cluster - Azure Arc Onboarding

Creates the Azure Arc connectedClusters resource and related deployment or configuration resources used to onboard an existing Kubernetes cluster. It grants Azure control-plane onboarding Actions and no Kubernetes API DataActions; the local kubeconfig used by the connect command separately determines what can be installed in the cluster.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 34e09817-6cbe-4d01-b1a2-e0eac5743d41

Control-plane actions (13)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the resource group where connected-cluster resources will be created. Subscription or management-group assignment is inherited by more resource groups and permits onboarding into each of them.

Common use cases (1)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Kubernetes Cluster - Azure Arc Onboarding on the dedicated onboarding resource group to the temporary platform identity. Run the documented connect workflow with separately protected cluster credentials, validate the connected agents, and remove the assignment when onboarding is complete.

Editorial sources (7)

Official Microsoft Learn documentation →