Azure Migration built-in role
Azure Local Migrate Owner
Creates and manages Azure Local-based Azure Migrate projects, performs appliance discovery and migration execution, and delegates migration-specific roles through a constrained assignment condition. Its permissions are Azure control-plane Actions only; it does not directly read guest file-system data through DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: fd8ea4d5-6509-4db0-bada-356ab233b4fb
Control-plane actions (64)
Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/writeMicrosoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/locations/readMicrosoft.Resources/checkResourceName/actionMicrosoft.Resources/deployments/validate/actionMicrosoft.Resources/deploymentScripts/writeMicrosoft.Resources/deploymentScripts/readMicrosoft.Resources/links/writeMicrosoft.Authorization/*/readMicrosoft.Authorization/locks/writeMicrosoft.Authorization/locks/deleteMicrosoft.Insights/alertRules/*Microsoft.Migrate/*Microsoft.ApplicationMigration/*Microsoft.OffAzure/*Microsoft.Support/*Microsoft.MySQLDiscovery/*Microsoft.DependencyMap/*Microsoft.KeyVault/vaults/*Microsoft.KeyVault/checkNameAvailability/readMicrosoft.HybridCompute/machines/readMicrosoft.HybridCompute/machines/writeMicrosoft.HybridCompute/machines/deleteMicrosoft.HybridCompute/register/actionMicrosoft.Network/virtualNetworks/readMicrosoft.Network/virtualNetworks/subnets/writeMicrosoft.Network/virtualNetworks/subnets/join/actionMicrosoft.Network/virtualNetworks/join/actionMicrosoft.Network/privateEndpoints/readMicrosoft.Network/privateEndpoints/writeMicrosoft.Network/privateEndpoints/privateDnsZoneGroups/writeMicrosoft.Network/privateDnsZones/writeMicrosoft.Network/privateDnsZones/virtualNetworkLinks/writeMicrosoft.Network/privateDnsZones/join/actionMicrosoft.Network/privateDnsZones/A/writeMicrosoft.Network/register/actionMicrosoft.Network/virtualNetworks/subnets/readMicrosoft.Network/privateEndpoints/privateDnsZoneGroups/readMicrosoft.Storage/storageAccounts/*Microsoft.GuestConfiguration/register/actionMicrosoft.HybridConnectivity/register/actionMicrosoft.RecoveryServices/vaults/*Microsoft.RecoveryServices/register/actionMicrosoft.RecoveryServices/operations/readMicrosoft.DataReplication/*/readMicrosoft.DataReplication/register/actionMicrosoft.DataReplication/replicationFabrics/*Microsoft.DataReplication/replicationVaults/*Microsoft.KeyVault/register/actionMicrosoft.AzureArcData/register/actionMicrosoft.Resources/links/readMicrosoft.AzureStackHCI/*/ReadMicrosoft.AzureStackHCI/LogicalNetworks/join/actionMicrosoft.AzureStackHCI/NetworkInterfaces/*Microsoft.AzureStackHCI/VirtualHardDisks/*Microsoft.AzureStackHCI/VirtualMachines/WriteMicrosoft.AzureStackHCI/VirtualMachineInstances/WriteMicrosoft.ExtendedLocation/customLocations/readMicrosoft.KubernetesConfiguration/extensions/readMicrosoft.ResourceConnector/appliances/readMicrosoft.Authorization/roleAssignments/writeMicrosoft.Authorization/roleAssignments/delete
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Conditions (1)
Condition version: 2.0
((!(ActionMatches{'Microsoft.Authorization/roleAssignments/write'})) OR (@Request[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals{7859c0b0-0bb9-4994-bd12-cd529af7d646, 1cfa4eac-9a23-481c-a793-bfb6958e836c, 17d1049b-9a84-46fb-8f53-869881c3d3ab, ba92f5b4-2d11-453d-a403-e96b0029c9fe, ba480ccd-6499-4709-b581-8f38bb215c63})) AND ((!(ActionMatches{'Microsoft.Authorization/roleAssignments/delete'})) OR (@Resource[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals{7859c0b0-0bb9-4994-bd12-cd529af7d646, 1cfa4eac-9a23-481c-a793-bfb6958e836c, 17d1049b-9a84-46fb-8f53-869881c3d3ab, ba92f5b4-2d11-453d-a403-e96b0029c9fe, ba480ccd-6499-4709-b581-8f38bb215c63}))
Assignable scopes (1)
/
Practical scope
Assign on the resource group containing the Azure Local migration project and supporting resources. Add target scope only when resources are in a separate group; a subscription assignment broadens project, target, and constrained-delegation authority.
Common use cases (2)
- Lead an end-to-end migration of Hyper-V or VMware VMs into Azure Local, including project creation, appliance registration, discovery, replication, cutover, and verification.
- Delegate Azure Local Migrate Execute Expert to an execution group while retaining project and migration governance.
Prerequisites (2)
- Azure Local 2503 or later, Arc resource bridge, source and target appliances, storage, Key Vault, an Azure Migrate project location, and supported source infrastructure must be prepared.
- Confirm whether the selected Hyper-V or automation path is preview and ensure the assigning principal can grant this privileged role at the project resource group.
Best practices (2)
- Keep this role with the small migration-owner group, delegate execution, and use eligible, time-bound access for the migration program.
- Use resource-group scope, audit constrained role assignments, and validate replication and target boot before decommissioning source VMs.
Security considerations (2)
- The role can create and delete the migration project, manage supporting storage, Key Vault, Arc, network, recovery, and Azure Local target resources, and initiate workload cutover.
- Its condition limits which migration and storage roles can be delegated, but the role remains privileged across the complete migration workflow.
Assignment guidance
Assign Azure Local Migrate Owner to the migration lead on the project resource group, preferably as eligible and time-bound. Delegate Execute Expert to the execution team, keep target access scoped, and remove both assignments when source decommissioning and project closure are complete.
Related roles (1)
- Azure Local Migrate Execute Expert: Runs and monitors replication and migration without project ownership.
Editorial sources (8)
- Azure built-in roles for Migration - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Eligible and time-bound role assignments in Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Overview of Azure Migrate based migration for Azure Local (preview) →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- What's new in Azure Migrate for Azure Local →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.