Azure Management and governance built-in role

New Relic APM Account Contributor

Manages legacy NewRelic.APM account resources and applications in Azure without granting access inside the New Relic service. Its control-plane definition also manages deployments, classic alerts, and support tickets and has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 5d28c62d-5b37-4476-8438-e587778df237

Control-plane actions (7)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign at the New Relic account resource or dedicated resource group. At broader scope, deployment, classic alert, support, and NewRelic.APM account operations reach all inherited resources.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign only for an existing NewRelic.APM account resource at its dedicated scope. Verify the resource provider and access model, and do not represent this Azure control-plane role as New Relic user or data access.

Common questions

When should I assign the New Relic APM Account Contributor Azure role?

Assign New Relic APM Account Contributor when you need to: Maintain an existing Azure NewRelic.APM account integration and its Azure-side application resources.; and Operate legacy New Relic APM account resources without granting New Relic application data access.. Practical scope: Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign at the New Relic account resource or dedicated resource group. At broader scope, deployment, classic alert, support, and NewRelic.APM account operations reach all inherited resources.

What permissions does the New Relic APM Account Contributor Azure role grant?

The role definition grants 7 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Insights/alertRules/*; Microsoft.ResourceHealth/availabilityStatuses/read; Microsoft.Resources/deployments/*; Microsoft.Resources/subscriptions/resourceGroups/read; and Microsoft.Support/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the New Relic APM Account Contributor Azure role?

Key considerations when assigning New Relic APM Account Contributor: The role can change or delete NewRelic.APM account resources and alter deployments or classic alerts in scope.; and It does not grant New Relic service data access, and current Azure Native New Relic resources use separate identities and role assignments.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →