Azure Migration built-in role
Azure Migrate Execute Expert
Performs Azure Migrate Execute phase operations, including replication, waves, test migrations, agentless and agent-based migrations, and progress monitoring. It uses control-plane Actions only and has a role-definition condition that limits role assignment creation and deletion to Storage Account Contributor and Storage Blob Data Contributor.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 1cfa4eac-9a23-481c-a793-bfb6958e836b
Control-plane actions (45)
Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/writeMicrosoft.Resources/subscriptions/locations/readMicrosoft.Resources/checkResourceName/actionMicrosoft.Resources/deploymentScripts/writeMicrosoft.Resources/deploymentScripts/readMicrosoft.Resources/links/writeMicrosoft.Authorization/*/readMicrosoft.Authorization/locks/writeMicrosoft.Authorization/locks/deleteMicrosoft.Insights/alertRules/*Microsoft.Migrate/*/readMicrosoft.ApplicationMigration/*/readMicrosoft.OffAzure/*/readMicrosoft.MySQLDiscovery/*/readMicrosoft.Support/*Microsoft.Network/networkInterfaces/readMicrosoft.Network/networkInterfaces/writeMicrosoft.Network/networkInterfaces/deleteMicrosoft.Network/virtualNetworks/readMicrosoft.Network/virtualNetworks/subnets/readMicrosoft.Storage/storageAccounts/*/readMicrosoft.Storage/storageAccounts/*/writeMicrosoft.Storage/storageAccounts/listKeys/actionMicrosoft.Compute/register/actionMicrosoft.Compute/availabilitySets/readMicrosoft.Compute/availabilitySets/vmSizes/readMicrosoft.Compute/diskEncryptionSets/readMicrosoft.Compute/skus/readMicrosoft.Compute/disks/readMicrosoft.Compute/disks/writeMicrosoft.Compute/disks/deleteMicrosoft.Compute/virtualMachines/readMicrosoft.Compute/virtualMachines/writeMicrosoft.Compute/virtualMachines/deleteMicrosoft.RecoveryServices/vaults/*Microsoft.RecoveryServices/register/actionMicrosoft.RecoveryServices/operations/readMicrosoft.Resources/links/readMicrosoft.DependencyMap/*/readMicrosoft.DependencyMap/maps/*/actionMicrosoft.Authorization/roleAssignments/writeMicrosoft.Authorization/roleAssignments/delete
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (6)
Microsoft.OffAzure/hypervSites/machines/inventoryinsights/pendingupdates/*Microsoft.OffAzure/hypervSites/machines/inventoryinsights/vulnerabilities/*Microsoft.OffAzure/serverSites/machines/inventoryinsights/pendingupdates/*Microsoft.OffAzure/serverSites/machines/inventoryinsights/vulnerabilities/*Microsoft.OffAzure/vmwareSites/machines/inventoryinsights/vulnerabilities/*Microsoft.OffAzure/vmwareSites/machines/inventoryinsights/pendingupdates/*
Conditions (1)
Condition version: 2.0
((!(ActionMatches{'Microsoft.Authorization/roleAssignments/write'})) OR (@Request[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals{17d1049b-9a84-46fb-8f53-869881c3d3ab, ba92f5b4-2d11-453d-a403-e96b0029c9fe})) AND ((!(ActionMatches{'Microsoft.Authorization/roleAssignments/delete'})) OR (@Resource[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals{17d1049b-9a84-46fb-8f53-869881c3d3ab, ba92f5b4-2d11-453d-a403-e96b0029c9fe}))
Assignable scopes (1)
/
Practical scope
Assign on the source resource group or subscription containing the Azure Migrate project and, when different, on the target resource group or subscription where workloads are created. Each assignment inherits to all migration and target resources below that scope.
Common use cases (2)
- Give a migration execution team permission to replicate workloads, run and monitor migration waves, and perform test and final migrations after planning is approved.
- Operate both agentless and agent-based server migrations without granting project creation or unrestricted access administration.
Prerequisites (2)
- The Azure Migrate project, discovery data, assessments, migration wave, source appliance, and target landing-zone resources must be prepared before execution.
- Assign the role at both source and target scopes when they differ, and ensure the required resource providers and target network, storage, compute, and recovery resources are available.
Best practices (2)
- Separate planning approval from execution and grant this role only for the approved migration window.
- Use resource-group scopes when possible, verify access at both source and target, and remove or expire the assignment after cutover and validation.
Security considerations (2)
- The role can create, change, and delete target compute, disk, network, recovery, and migration resources and can initiate workload cutover.
- Its role-assignment condition permits only two storage roles; it is not general access administration, but those delegated storage assignments still expose migration staging resources at their assigned scopes.
Assignment guidance
Have Azure Migrate Owner assign Execute Expert to the migration execution group on the source project resource group and the target resource group when separate. Confirm the constrained storage-role condition, use an eligible or time-bound assignment, and remove it after migration verification.
Related roles (2)
- Azure Migrate Owner: Creates and manages the Azure Migrate project and can delegate the phase-specific Azure Migrate roles through its constrained assignment permission.
- Azure Migrate Decide and Plan Expert: Microsoft documents it for discovery, inventory, dependency, business-case, wave, and assessment work rather than migration execution.
Editorial sources (7)
- Azure built-in roles for Migration - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Eligible and time-bound role assignments in Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Prepare Azure accounts for Azure Migrate using built-in roles →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.