Azure Migration built-in role

Azure Local Migrate Owner

Creates and manages Azure Local-based Azure Migrate projects, performs appliance discovery and migration execution, and delegates migration-specific roles through a constrained assignment condition. Its permissions are Azure control-plane Actions only; it does not directly read guest file-system data through DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: fd8ea4d5-6509-4db0-bada-356ab233b4fb

Control-plane actions (64)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Conditions (1)

Assignable scopes (1)

Practical scope

Assign on the resource group containing the Azure Local migration project and supporting resources. Add target scope only when resources are in a separate group; a subscription assignment broadens project, target, and constrained-delegation authority.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Azure Local Migrate Owner to the migration lead on the project resource group, preferably as eligible and time-bound. Delegate Execute Expert to the execution team, keep target access scoped, and remove both assignments when source decommissioning and project closure are complete.

Related roles (1)

Common questions

When should I assign the Azure Local Migrate Owner Azure role?

Assign Azure Local Migrate Owner when you need to: Lead an end-to-end migration of Hyper-V or VMware VMs into Azure Local, including project creation, appliance registration, discovery, replication, cutover, and verification.; and Delegate Azure Local Migrate Execute Expert to an execution group while retaining project and migration governance.. Practical scope: Assign on the resource group containing the Azure Local migration project and supporting resources. Add target scope only when resources are in a separate group; a subscription assignment broadens project, target, and constrained-delegation authority.

What permissions does the Azure Local Migrate Owner Azure role grant?

The role definition grants 64 combined control-plane and data-plane actions. Representative operations include: Microsoft.Resources/subscriptions/resourceGroups/read; Microsoft.Resources/deployments/*; Microsoft.Resources/subscriptions/resourceGroups/write; Microsoft.Resources/subscriptions/read; Microsoft.Resources/subscriptions/locations/read; and Microsoft.Resources/checkResourceName/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure Local Migrate Owner Azure role?

Key considerations when assigning Azure Local Migrate Owner: The role can create and delete the migration project, manage supporting storage, Key Vault, Arc, network, recovery, and Azure Local target resources, and initiate workload cutover.; and Its condition limits which migration and storage roles can be delegated, but the role remains privileged across the complete migration workflow.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (8)

Official Microsoft Learn documentation →