Azure Identity built-in role

Managed Identity Operator

Reads user-assigned managed identities and attaches existing identities to supported Azure resources. It does not create, update, or delete the identity and does not grant the identity permissions on downstream resources.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: f1a07417-d97a-45cb-824c-7a7467783830

Control-plane actions (7)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The built-in definition is available throughout the Azure hierarchy. Effective access is limited to the selected scope and inherited child scopes, ideally the specific identity or identity resource group. Its permissions are control-plane Actions and it has no DataActions.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Managed Identity Operator to workload deployment principals that must attach approved existing identities, scoped to those identities. Grant target-resource write access separately, and verify the attached identity has only the downstream permissions the workload needs. Use Managed Identity Contributor only for lifecycle or federated-credential administration.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →