Azure Containers built-in role

Azure Kubernetes Service Arc Cluster Admin Role

Azure Kubernetes Service Arc Cluster Admin Role authorizes retrieval of the admin certificate-based kubeconfig for AKS enabled by Azure Arc cluster through an Azure control-plane list-credential Action. The returned admin kubeconfig provides administrative cluster access and is distinct from Azure RBAC Kubernetes DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: b29efa5f-7782-4dc3-9537-4d5bc70a5e9f

Control-plane actions (3)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual AKS enabled by Azure Arc cluster. A resource-group or broader assignment is inherited by every matching resource below it and permits credential retrieval for each inherited cluster.

Common use cases (1)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Azure Kubernetes Service Arc Cluster Admin Role directly on the AKS enabled by Azure Arc cluster to the identity that must retrieve the admin certificate-based kubeconfig. Keep it temporary or eligible, prefer ordinary user access for daily operations, securely delete downloaded credentials after use.

Related roles (1)

Editorial sources (6)

Official Microsoft Learn documentation →