Azure Networking built-in role

Private DNS Zone Contributor

Manages Azure Private DNS zones, records, operation results, operation statuses, and virtual-network links without general virtual-network write access or Azure RBAC delegation. It can read and join virtual networks and also grants deployment, classic alert-rule, support-ticket, authorization-read, and resource-group-read Actions. It has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: b12aa53e-6015-4669-85d0-8515ebb3ae7f

Control-plane actions (10)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Private DNS documents assignment at subscription, resource group, individual zone, or individual record-set scope, with inheritance from parent scopes. At resource-group or subscription scope, the deployment, classic alert, and support permissions reach corresponding resources throughout that broad scope, not only Private DNS zones. Virtual-network authority is limited to read and join Actions.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Private DNS Zone Contributor at the specific private zone or dedicated DNS resource group the team owns. Approve virtual-network links and autoregistration deliberately, and avoid broad scope unless the ancillary deployment, alert, and support permissions are also required.

Editorial sources (7)

Official Microsoft Learn documentation →