Azure Migration built-in role
Azure Migrate Service Reader
Grants required access to the system assigned managed identity of Azure Migrate project resource.
Control-plane and data-plane permissions below are imported directly from Microsoft Learn. In-app editorial guidance (use cases, best practices, security notes) and least-privilege recommendations are still pending review.
Role definition ID: ba480ccd-6499-4709-b581-8f38bb215c63
Control-plane actions (11)
Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Resources/deployments/*Microsoft.ApplicationMigration/*/readMicrosoft.Migrate/*/readMicrosoft.OffAzure/*/readMicrosoft.MySQLDiscovery/*/readMicrosoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectableItems/readMicrosoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/readMicrosoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/