Azure Migration built-in role

Azure Migrate Execute Expert

Performs Azure Migrate Execute phase operations, including replication, waves, test migrations, agentless and agent-based migrations, and progress monitoring. It uses control-plane Actions only and has a role-definition condition that limits role assignment creation and deletion to Storage Account Contributor and Storage Blob Data Contributor.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 1cfa4eac-9a23-481c-a793-bfb6958e836b

Control-plane actions (45)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (6)

Conditions (1)

Assignable scopes (1)

Practical scope

Assign on the source resource group or subscription containing the Azure Migrate project and, when different, on the target resource group or subscription where workloads are created. Each assignment inherits to all migration and target resources below that scope.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Have Azure Migrate Owner assign Execute Expert to the migration execution group on the source project resource group and the target resource group when separate. Confirm the constrained storage-role condition, use an eligible or time-bound assignment, and remove it after migration verification.

Related roles (2)

Editorial sources (7)

Official Microsoft Learn documentation →