Azure Containers built-in role
Azure Kubernetes Service Arc Contributor Role
Creates, scales, upgrades, updates, and deletes AKS enabled by Azure Arc cluster resources and can retrieve the connected cluster's user credential. It has no Kubernetes API DataActions, so the retrieved user identity remains subject to the cluster's configured authorization.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 5d3f1697-4507-4d08-bb4a-477695db5f82
Control-plane actions (37)
Microsoft.HybridContainerService/Locations/operationStatuses/readMicrosoft.HybridContainerService/Locations/operationStatuses/writeMicrosoft.HybridContainerService/Operations/readMicrosoft.HybridContainerService/kubernetesVersions/readMicrosoft.HybridContainerService/kubernetesVersions/writeMicrosoft.HybridContainerService/kubernetesVersions/deleteMicrosoft.HybridContainerService/provisionedClusterInstances/readMicrosoft.HybridContainerService/provisionedClusterInstances/writeMicrosoft.HybridContainerService/provisionedClusterInstances/deleteMicrosoft.HybridContainerService/provisionedClusterInstances/agentPools/readMicrosoft.HybridContainerService/provisionedClusterInstances/agentPools/writeMicrosoft.HybridContainerService/provisionedClusterInstances/agentPools/deleteMicrosoft.HybridContainerService/provisionedClusterInstances/upgradeProfiles/readMicrosoft.HybridContainerService/skus/readMicrosoft.HybridContainerService/skus/writeMicrosoft.HybridContainerService/skus/deleteMicrosoft.HybridContainerService/virtualNetworks/readMicrosoft.HybridContainerService/virtualNetworks/writeMicrosoft.HybridContainerService/virtualNetworks/deleteMicrosoft.ExtendedLocation/customLocations/deploy/actionMicrosoft.ExtendedLocation/customLocations/readMicrosoft.Kubernetes/connectedClusters/ReadMicrosoft.Kubernetes/connectedClusters/WriteMicrosoft.Kubernetes/connectedClusters/DeleteMicrosoft.Kubernetes/connectedClusters/listClusterUserCredential/actionMicrosoft.AzureStackHCI/clusters/readMicrosoft.Resources/deployments/readMicrosoft.Resources/deployments/writeMicrosoft.Resources/deployments/deleteMicrosoft.Resources/deployments/cancel/actionMicrosoft.Resources/deployments/validate/actionMicrosoft.Resources/deployments/whatIf/actionMicrosoft.Resources/deployments/exportTemplate/actionMicrosoft.Resources/deployments/operations/readMicrosoft.Resources/deployments/operationstatuses/readMicrosoft.HybridContainerService/provisionedClusterInstances/hybridIdentityMetadata/deleteMicrosoft.HybridContainerService/provisionedClusterInstances/hybridIdentityMetadata/write
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on an individual provisioned-cluster resource or its dedicated resource group. A parent assignment is inherited by every AKS Arc cluster below it and permits lifecycle changes across those clusters.
Common use cases (1)
- Allow a platform operator to manage the lifecycle and configuration of approved AKS enabled by Azure Arc clusters and retrieve an ordinary user credential for authorized cluster access.
Prerequisites (2)
- The Azure Local or supported Arc infrastructure, custom location, networking, identity, and cluster authorization model must be configured.
- Grant an appropriate Kubernetes authorization role separately; use the narrower Arc Cluster User role when user credential retrieval is needed without lifecycle management, and grant admin kubeconfig retrieval separately only for exceptional recovery.
Best practices (2)
- Keep lifecycle administration with the platform team and use namespace-scoped Kubernetes roles for application teams.
- Test upgrades and scaling changes and avoid combining standing contributor access with admin kubeconfig retrieval unless operationally required.
Security considerations (2)
- Cluster lifecycle changes can affect all workloads, nodes, networking, identity, and availability on the AKS Arc cluster.
- The included user credential retrieval creates a cluster connection path even though the role has no Kubernetes API DataActions; combining it with broad Kubernetes authorization or the separate admin credential role creates end-to-end authority.
Assignment guidance
Assign directly on the AKS Arc cluster or dedicated cluster resource group only to the platform team that needs both lifecycle management and user credential retrieval. Use Cluster User for credential-only access, Cluster Admin only for exceptional recovery, and Azure Arc Kubernetes data roles for workload authorization.
Related roles (2)
- Azure Kubernetes Service Arc Cluster User Role: Narrower user kubeconfig retrieval without AKS Arc lifecycle management.
- Azure Kubernetes Service Arc Cluster Admin Role: Retrieves sensitive administrator credentials without lifecycle management.
Editorial sources (6)
- Azure built-in roles for Containers - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Access and identity options for AKS enabled by Azure Arc →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.