Azure Migration built-in role

Azure Local Migrate Owner

Creates and manages Azure Local-based Azure Migrate projects, performs appliance discovery and migration execution, and delegates migration-specific roles through a constrained assignment condition. Its permissions are Azure control-plane Actions only; it does not directly read guest file-system data through DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: fd8ea4d5-6509-4db0-bada-356ab233b4fb

Control-plane actions (64)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Conditions (1)

Assignable scopes (1)

Practical scope

Assign on the resource group containing the Azure Local migration project and supporting resources. Add target scope only when resources are in a separate group; a subscription assignment broadens project, target, and constrained-delegation authority.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Azure Local Migrate Owner to the migration lead on the project resource group, preferably as eligible and time-bound. Delegate Execute Expert to the execution team, keep target access scoped, and remove both assignments when source decommissioning and project closure are complete.

Related roles (1)

Editorial sources (8)

Official Microsoft Learn documentation →