Azure Migration built-in role

Azure Migrate Owner

Creates, manages, and deletes Azure Migrate projects and performs the complete Decide, Plan, and Execute journey. It uses control-plane Actions only and has a condition that limits delegated role assignments to Azure Migrate phase roles and the two documented storage roles rather than arbitrary Azure roles.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: fd8ea4d5-6509-4db0-bada-356ab233b4fa

Control-plane actions (68)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Conditions (1)

Assignable scopes (1)

Practical scope

Assign on the resource group where the Azure Migrate project is created. Subscription scope can register providers and support cross-resource operations but inherits authority to every Azure Migrate project and supporting resource below it.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

A subscription or resource-group owner should assign Azure Migrate Owner to the migration project lead on the project resource group, preferably as eligible and time-bound. The project lead should delegate phase roles to groups, not broaden this owner assignment, and remove access when the migration program closes.

Related roles (2)

Editorial sources (7)

Official Microsoft Learn documentation →