Azure Security built-in role
Managed HSM contributor
Manages Azure Key Vault Managed HSM resources in the Azure control plane, including Managed HSM lifecycle and deleted-HSM recovery or purge operations. It has no DataActions and does not grant access to HSM-backed keys, local role assignments, backups, restores, or the security domain.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 18500a29-7fe2-46b2-a342-b16a415e101d
Control-plane actions (5)
Microsoft.KeyVault/managedHSMs/*Microsoft.KeyVault/deletedManagedHsms/readMicrosoft.KeyVault/locations/deletedManagedHsms/readMicrosoft.KeyVault/locations/deletedManagedHsms/purge/actionMicrosoft.KeyVault/locations/managedHsmOperationResults/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual Managed HSM or its dedicated resource group. Parent-scope Azure RBAC assignments are inherited for the control plane. Managed HSM key access is a separate data plane enforced by Managed HSM local RBAC at HSM or key scope and is not inherited from this Azure role.
Common use cases (2)
- Provision, configure, move, update, delete, recover, or purge a Managed HSM resource in an approved lifecycle workflow.
- Operate Managed HSM control-plane properties and tags while a separate security team controls keys and local RBAC.
Prerequisites (3)
- Define the Microsoft Entra tenant, region, resource group, initial data-plane administrators, security-domain process, and recovery ownership before creating the HSM.
- Establish separate Managed HSM local RBAC assignments for every required key, backup, restore, security-domain, or data-plane administration task.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at the HSM or parent scope.
Best practices (3)
- Separate Azure control-plane HSM lifecycle administration from Managed HSM local RBAC and key custody.
- Assign at the individual HSM or dedicated resource group and use just-in-time privileged access for human administrators.
- Protect deletion and purge procedures, retain the required security-domain material, and audit both Azure RBAC and local RBAC independently.
Security considerations (3)
- The role can delete or permanently purge a Managed HSM resource, causing outage or irreversible loss if recovery and security-domain procedures fail.
- Control-plane access does not grant key or local-role access by design, and it must never be represented as a Managed HSM crypto role.
- Conversely, removing local data-plane access does not prevent this Azure control-plane administrator from changing or deleting the HSM resource.
Assignment guidance
Assign Managed HSM contributor to the infrastructure team at the individual HSM or dedicated resource-group scope. Assign Managed HSM local RBAC separately to key custodians and workloads, preserve separation of duties, and require explicit approval for delete, recover, or purge operations.
Editorial sources (6)
- Azure built-in roles for Security →
Supports: Description, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Azure Key Vault Managed HSM access control →
Supports: Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Secure your Azure Key Vault →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.