Azure Management and governance built-in role
Management Group Contributor
Creates, updates, and deletes management groups and moves subscriptions into or out of them, while reading Azure authorization metadata. It does not create role assignments or policy assignments, but hierarchy changes alter which inherited RBAC and policy assignments apply to subscriptions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 5d58bcaf-24a5-4b20-bdb6-eed9f69fbe4c
Control-plane actions (7)
Microsoft.Management/managementGroups/deleteMicrosoft.Management/managementGroups/readMicrosoft.Management/managementGroups/subscriptions/deleteMicrosoft.Management/managementGroups/subscriptions/writeMicrosoft.Management/managementGroups/writeMicrosoft.Management/managementGroups/subscriptions/readMicrosoft.Authorization/*/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at the management group whose child hierarchy the administrator manages. Management-group role and policy assignments inherit to descendants, and a subscription can belong to only one management-group path, so moves change its inherited governance context.
Common use cases (2)
- Create and maintain an approved management-group hierarchy.
- Move subscriptions between management groups during organizational, landing-zone, or lifecycle changes.
Prerequisites (2)
- The tenant root and target hierarchy must exist, and the operator needs appropriate access at both source and destination scopes for a move.
- Review inherited role assignments, policy assignments, exemptions, and hierarchy protection before changing placement.
Best practices (2)
- Limit the role to the platform governance team and use eligible access for hierarchy changes.
- Model and approve the inherited policy and RBAC result before moving a production subscription.
Security considerations (2)
- Moving a subscription changes inherited policy and RBAC, potentially granting unintended access or removing required controls.
- Deleting or restructuring management groups can disrupt organization-wide governance even though this role has no DataActions or role-assignment writes.
Assignment guidance
Assign at the smallest management group whose children the governance operator owns. Require change control for subscription moves and keep hierarchy settings, policy authoring, and role assignment delegation on separately approved roles.
Related roles (3)
- Management Group Reader: Read-only hierarchy and authorization view.
- Hierarchy Settings Administrator: Separate tenant-root authority over hierarchy settings.
- Resource Policy Contributor: Separate role for policy definitions, assignments, exemptions, and remediation tasks.
Editorial sources (6)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- What are Azure management groups? →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Protect your resource hierarchy →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.