Azure Security built-in role

Locks Contributor

Reads, creates, updates, and deletes Azure management locks. A lock can impose CanNotDelete or ReadOnly restrictions that override the permissions of users and roles, but locks apply only to Azure control-plane operations and do not protect or restrict data-plane operations.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 28bf596f-4eb7-45ce-b5bc-6cf482fec137

Control-plane actions (3)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Locks can be applied to a subscription, resource group, or individual resource, not to a management group. A parent lock is inherited by existing and future child resources, and the most restrictive lock in the inheritance chain takes precedence. Assign this role only at the boundary whose locks the principal is authorized to control.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Locks Contributor to a small governance or platform group at the subscription, resource group, or resource boundary it protects. Require change approval for lock removal, test service behavior before ReadOnly locks, and never describe a management lock as a data-protection control.

Editorial sources (5)

Official Microsoft Learn documentation →