Azure Management and governance built-in role
Managed Services Registration assignment Delete Role
Lets authorized users in an Azure Lighthouse managing tenant read and delete the registration assignment that delegates access to their tenant. It does not create a delegation, change its authorizations, or grant workload DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 91c1777a-f3dc-4fae-b103-61d183457e46
Control-plane actions (3)
Microsoft.ManagedServices/registrationAssignments/readMicrosoft.ManagedServices/registrationAssignments/deleteMicrosoft.ManagedServices/operationStatuses/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign through the Azure Lighthouse delegation at the customer subscription or resource-group scope whose registration assignment the managing tenant may remove. The effect is cross-tenant and removal ends delegated access at that scope.
Common use cases (2)
- Allow a managing-tenant operator to remove its own Azure Lighthouse delegation when managed-service access must end.
- Support a controlled provider offboarding workflow without requiring the customer tenant to perform the removal.
Prerequisites (2)
- An Azure Lighthouse registration assignment must already delegate the role to an identity in the managing tenant.
- Confirm the customer, offer, subscription or resource-group scope, and offboarding impact before deletion.
Best practices (2)
- Grant only to a small provider offboarding group and require customer or contract approval before removal.
- Inventory monitoring, automation, incident response, and other dependencies that will lose delegated access.
Security considerations (2)
- Deleting the registration assignment removes the managing tenant's delegated access and can immediately break provider operations.
- The role is narrowly scoped to registration-assignment deletion, but the cross-tenant access effect is significant and may be difficult to reverse without a new onboarding deployment.
Assignment guidance
Include this role in a Lighthouse authorization only for the provider identity responsible for approved delegation removal. Scope it to the customer delegation, verify dependencies, and record the offboarding decision before deletion.
Editorial sources (5)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Remove access to a delegation →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.