Azure Security built-in role

Managed HSM contributor

Manages Azure Key Vault Managed HSM resources in the Azure control plane, including Managed HSM lifecycle and deleted-HSM recovery or purge operations. It has no DataActions and does not grant access to HSM-backed keys, local role assignments, backups, restores, or the security domain.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 18500a29-7fe2-46b2-a342-b16a415e101d

Control-plane actions (5)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Managed HSM or its dedicated resource group. Parent-scope Azure RBAC assignments are inherited for the control plane. Managed HSM key access is a separate data plane enforced by Managed HSM local RBAC at HSM or key scope and is not inherited from this Azure role.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Managed HSM contributor to the infrastructure team at the individual HSM or dedicated resource-group scope. Assign Managed HSM local RBAC separately to key custodians and workloads, preserve separation of duties, and require explicit approval for delete, recover, or purge operations.

Editorial sources (6)

Official Microsoft Learn documentation →