Azure Migration built-in role

Migrate Arc Discovery Reader - Preview

Reads Azure Arc-enabled server metadata and Arc-enabled SQL Server metadata, telemetry, performance, and migration-suitability information for Azure Migrate Arc-based discovery. It is a preview, control-plane-only role with no DataActions and does not change the Arc resources.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 5d5dddae-e124-4753-972d-aae60b37deb4

Microsoft Learn identifies this role as Preview in its published role name.

Control-plane actions (8)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on every subscription containing Arc resources selected in the Azure Migrate project scope. Manual sync uses the user identity; automatic daily sync uses the Azure Migrate project system-assigned managed identity.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Migrate Arc Discovery Reader - Preview on each in-scope Arc subscription to the user performing manual sync or to the Azure Migrate project managed identity for automatic sync. Keep the project scope and assignments aligned and remove access when discovery ends.

Related roles (2)

Common questions

When should I assign the Migrate Arc Discovery Reader - Preview Azure role?

Assign Migrate Arc Discovery Reader - Preview when you need to: Let a user manually synchronize Arc-enabled VMware or Hyper-V servers and Arc-enabled SQL Server inventory into a new Azure Migrate project for assessments and business cases.; and Authorize the Azure Migrate project managed identity to synchronize scoped Arc resource metadata automatically every 24 hours.. Practical scope: Assign on every subscription containing Arc resources selected in the Azure Migrate project scope. Manual sync uses the user identity; automatic daily sync uses the Azure Migrate project system-assigned managed identity.

What permissions does the Migrate Arc Discovery Reader - Preview Azure role grant?

The role definition grants 8 combined control-plane and data-plane actions. Representative operations include: Microsoft.Resources/subscriptions/resourceGroups/read; Microsoft.AzureArcData/sqlServerInstances/read; Microsoft.AzureArcData/sqlServerInstances/databases/read; Microsoft.AzureArcData/sqlServerInstances/availabilityGroups/read; Microsoft.AzureArcData/sqlServerInstances/getTelemetry/action; and Microsoft.AzureArcData/sqlServerInstances/availabilityGroups/getDetailView/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Migrate Arc Discovery Reader - Preview Azure role?

Key considerations when assigning Migrate Arc Discovery Reader - Preview: The role exposes server configuration, operating system, hypervisor, SQL inventory, telemetry, performance, and migration-suitability metadata across each assigned subscription.; and Automatic sync repeats this collection daily under the project managed identity; parent or unrelated subscription assignments broaden discovery beyond the intended project scope.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (8)

Official Microsoft Learn documentation →