Azure Migration built-in role

Azure Migrate Owner

Creates, manages, and deletes Azure Migrate projects and performs the complete Decide, Plan, and Execute journey. It uses control-plane Actions only and has a condition that limits delegated role assignments to Azure Migrate phase roles and the two documented storage roles rather than arbitrary Azure roles.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: fd8ea4d5-6509-4db0-bada-356ab233b4fa

Control-plane actions (68)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Conditions (1)

Assignable scopes (1)

Practical scope

Assign on the resource group where the Azure Migrate project is created. Subscription scope can register providers and support cross-resource operations but inherits authority to every Azure Migrate project and supporting resource below it.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

A subscription or resource-group owner should assign Azure Migrate Owner to the migration project lead on the project resource group, preferably as eligible and time-bound. The project lead should delegate phase roles to groups, not broaden this owner assignment, and remove access when the migration program closes.

Related roles (2)

Common questions

When should I assign the Azure Migrate Owner Azure role?

Assign Azure Migrate Owner when you need to: Give the migration program owner end-to-end project creation, discovery, assessment, wave, replication, migration, and support capabilities.; and Delegate Decide and Plan Expert and Execute Expert to planning and execution teams while retaining project ownership.. Practical scope: Assign on the resource group where the Azure Migrate project is created. Subscription scope can register providers and support cross-resource operations but inherits authority to every Azure Migrate project and supporting resource below it.

What permissions does the Azure Migrate Owner Azure role grant?

The role definition grants 68 combined control-plane and data-plane actions. Representative operations include: Microsoft.Resources/subscriptions/resourceGroups/read; Microsoft.Resources/deployments/*; Microsoft.Resources/subscriptions/resourceGroups/write; Microsoft.Resources/subscriptions/read; Microsoft.Resources/subscriptions/locations/read; and Microsoft.Resources/checkResourceName/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure Migrate Owner Azure role?

Key considerations when assigning Azure Migrate Owner: The role controls the migration project and supporting Key Vault, storage, network, compute, recovery, and migration resources and can execute workload cutovers.; and Its conditional delegation is narrower than general Owner, but it can still grant migration and storage roles at inherited scopes and should be treated as privileged.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →