Azure Networking built-in role
Private DNS Zone Contributor
Manages Azure Private DNS zones, records, operation results, operation statuses, and virtual-network links without general virtual-network write access or Azure RBAC delegation. It can read and join virtual networks and also grants deployment, classic alert-rule, support-ticket, authorization-read, and resource-group-read Actions. It has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: b12aa53e-6015-4669-85d0-8515ebb3ae7f
Control-plane actions (10)
Microsoft.Insights/alertRules/*Microsoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*Microsoft.Network/privateDnsZones/*Microsoft.Network/privateDnsOperationResults/*Microsoft.Network/privateDnsOperationStatuses/*Microsoft.Network/virtualNetworks/readMicrosoft.Network/virtualNetworks/join/actionMicrosoft.Authorization/*/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Private DNS documents assignment at subscription, resource group, individual zone, or individual record-set scope, with inheritance from parent scopes. At resource-group or subscription scope, the deployment, classic alert, and support permissions reach corresponding resources throughout that broad scope, not only Private DNS zones. Virtual-network authority is limited to read and join Actions.
Common use cases (2)
- Manage private DNS zones and records for a defined application or platform namespace.
- Create and maintain resolution or registration links between approved virtual networks and private DNS zones, including autoregistration configuration.
Prerequisites (3)
- Create or identify the private DNS zone and the virtual networks that require name resolution, and decide whether each link is for resolution only or registration with autoregistration.
- Confirm private-zone and virtual-network-link limits and restrictions, including that classic deployment-model virtual networks are unsupported.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at the target scope.
Best practices (3)
- Assign at a private-zone or dedicated DNS resource-group scope rather than granting broad subscription access.
- Review every virtual-network link and enable autoregistration only where automatic VM record lifecycle is intended.
- Protect critical zones and records with appropriate resource locks, and account for custom DNS forwarding requirements when linked networks do not use Azure-provided DNS.
Security considerations (3)
- Deleting or changing a private zone or record can interrupt internal name resolution and application connectivity.
- Adding a virtual-network link changes which workloads can resolve the zone; enabling autoregistration also changes how VM records are created and removed.
- At broad scope, deployment, classic alert-rule, and support-ticket management extends beyond Private DNS. The role has no DataActions, but private DNS control can still redirect or disrupt internal traffic.
Assignment guidance
Assign Private DNS Zone Contributor at the specific private zone or dedicated DNS resource group the team owns. Approve virtual-network links and autoregistration deliberately, and avoid broad scope unless the ancillary deployment, alert, and support permissions are also required.
Editorial sources (7)
- Azure built-in roles for Networking →
Supports: Description, Practical scope, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Azure Private DNS zone overview →
Supports: Common use cases, Prerequisites, Best practices. Retrieved 2026-07-16.
- Protecting private DNS zones and records →
Supports: Practical scope, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Virtual network links for Azure Private DNS zones →
Supports: Description, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.