Azure Management and governance built-in role
Managed Application Contributor Role
Creates and manages Azure Managed Application resources and deployments and can create or delete resource groups, while reading resources broadly. It has no DataActions and does not by itself define publisher access to the managed resource group.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 641177b8-a67a-45b9-a033-47bc880bb21e
Control-plane actions (5)
*/readMicrosoft.Solutions/applications/*Microsoft.Solutions/register/actionMicrosoft.Resources/subscriptions/resourceGroups/*Microsoft.Resources/deployments/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign at the resource group that contains customer-facing managed application resources where practical; broader scope extends resource-group, deployment, and Managed Application lifecycle authority.
Common use cases (2)
- Create, update, and delete service catalog or Marketplace managed application instances.
- Operate the customer-side lifecycle of managed application resources and their deployments.
Prerequisites (2)
- An approved managed application definition or Marketplace offer and deployment parameters must be available.
- Review the managed resource group, publisher authorization, and JIT access model before deployment.
Best practices (2)
- Assign in a dedicated resource group and review the publisher access defined by the managed application separately.
- Use Operator when the principal needs only supported actions rather than resource-group and deployment management.
Security considerations (2)
- The role can create or delete resource groups and deploy or remove Managed Applications, affecting all resources in the managed solution lifecycle.
- It has no DataActions, but broad control-plane reads and deployment authority make it a privileged role rather than a least-privilege default.
Assignment guidance
Assign to trusted managed-application lifecycle administrators at the dedicated application resource group. Keep publisher JIT access and Azure RBAC delegation reviewed separately, and use Operator for action-only duties.
Related roles (1)
- Managed Application Operator Role: Narrower role for reading and invoking supported actions on Managed Application resources.
Editorial sources (5)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Azure Managed Applications overview →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.