Azure Management and governance built-in role
New Relic APM Account Contributor
Manages legacy NewRelic.APM account resources and applications in Azure without granting access inside the New Relic service. Its control-plane definition also manages deployments, classic alerts, and support tickets and has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 5d28c62d-5b37-4476-8438-e587778df237
Control-plane actions (7)
Microsoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*NewRelic.APM/accounts/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign at the New Relic account resource or dedicated resource group. At broader scope, deployment, classic alert, support, and NewRelic.APM account operations reach all inherited resources.
Common use cases (2)
- Maintain an existing Azure NewRelic.APM account integration and its Azure-side application resources.
- Operate legacy New Relic APM account resources without granting New Relic application data access.
Prerequisites (2)
- Confirm that the environment uses the NewRelic.APM resource type rather than assuming this role governs every current Azure Native New Relic workflow.
- Configure New Relic user access and Azure Native monitoring identities separately where applicable.
Best practices (2)
- Scope to the dedicated integration resource group and review whether a current Azure Native New Relic role pattern should replace the legacy account role.
- Keep Azure resource administration separate from New Relic organization and application access.
Security considerations (2)
- The role can change or delete NewRelic.APM account resources and alter deployments or classic alerts in scope.
- It does not grant New Relic service data access, and current Azure Native New Relic resources use separate identities and role assignments.
Assignment guidance
Assign only for an existing NewRelic.APM account resource at its dedicated scope. Verify the resource provider and access model, and do not represent this Azure control-plane role as New Relic user or data access.
Editorial sources (5)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Manage Azure Native New Relic Service →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.