Azure Management and governance built-in role

Managed Application Contributor Role

Creates and manages Azure Managed Application resources and deployments and can create or delete resource groups, while reading resources broadly. It has no DataActions and does not by itself define publisher access to the managed resource group.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 641177b8-a67a-45b9-a033-47bc880bb21e

Control-plane actions (5)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign at the resource group that contains customer-facing managed application resources where practical; broader scope extends resource-group, deployment, and Managed Application lifecycle authority.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign to trusted managed-application lifecycle administrators at the dedicated application resource group. Keep publisher JIT access and Azure RBAC delegation reviewed separately, and use Operator for action-only duties.

Related roles (1)

Editorial sources (5)

Official Microsoft Learn documentation →