Azure Management and governance built-in role

Managed Application Contributor Role

Creates and manages Azure Managed Application resources and deployments and can create or delete resource groups, while reading resources broadly. It has no DataActions and does not by itself define publisher access to the managed resource group.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 641177b8-a67a-45b9-a033-47bc880bb21e

Control-plane actions (5)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign at the resource group that contains customer-facing managed application resources where practical; broader scope extends resource-group, deployment, and Managed Application lifecycle authority.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign to trusted managed-application lifecycle administrators at the dedicated application resource group. Keep publisher JIT access and Azure RBAC delegation reviewed separately, and use Operator for action-only duties.

Related roles (1)

Common questions

When should I assign the Managed Application Contributor Role Azure role?

Assign Managed Application Contributor Role when you need to: Create, update, and delete service catalog or Marketplace managed application instances.; and Operate the customer-side lifecycle of managed application resources and their deployments.. Practical scope: Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign at the resource group that contains customer-facing managed application resources where practical; broader scope extends resource-group, deployment, and Managed Application lifecycle authority.

What permissions does the Managed Application Contributor Role Azure role grant?

The role definition grants 5 combined control-plane and data-plane actions. Representative operations include: */read; Microsoft.Solutions/applications/*; Microsoft.Solutions/register/action; Microsoft.Resources/subscriptions/resourceGroups/*; and Microsoft.Resources/deployments/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Managed Application Contributor Role Azure role?

Key considerations when assigning Managed Application Contributor Role: The role can create or delete resource groups and deploy or remove Managed Applications, affecting all resources in the managed solution lifecycle.; and It has no DataActions, but broad control-plane reads and deployment authority make it a privileged role rather than a least-privilege default.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →