Azure Migration built-in role

Azure Local Migrate Execute Expert

Runs and monitors Azure Migrate replication and migration into Azure Local with restricted access. It uses Azure control-plane Actions only and conditionally limits storage role assignments; Hyper-V migration and some automation paths remain preview, while the same role also supports the documented VMware migration flow.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 1cfa4eac-9a23-481c-a793-bfb6958e836c

Control-plane actions (40)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (6)

Conditions (1)

Assignable scopes (1)

Practical scope

Assign on the resource group containing the Azure Local-based Azure Migrate project and on the Azure Local target resource group when separate. Avoid subscription scope unless the documented cross-scope workflow requires it.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Azure Local Migrate Execute Expert to the migration execution group on the Azure Local migration project and target resource groups for the approved window. Verify the target and preview status, keep the role condition intact, and remove access after migrated VMs are validated.

Related roles (1)

Editorial sources (8)

Official Microsoft Learn documentation →