Azure Management and governance built-in role
Resource Policy Contributor
Creates and modifies Azure Policy definitions, initiatives, assignments, exemptions, remediations, and policy-related resources while reading the Azure hierarchy and all resources. It can create support tickets but does not grant Azure RBAC access to users.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 36243c78-bf99-498c-9df9-86d9f8d28608
Control-plane actions (9)
*/readMicrosoft.Authorization/policyassignments/*Microsoft.Authorization/policydefinitions/*Microsoft.Authorization/policyexemptions/*Microsoft.Authorization/policyenrollments/*Microsoft.Authorization/policysetdefinitions/*Microsoft.PolicyInsights/*Microsoft.Resources/deployments/*Microsoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Policy definitions and assignments can target management groups, subscriptions, and resource groups, and policy effects apply to resources beneath the assignment scope. A broad role assignment enables governance changes across inherited child scopes.
Common use cases (2)
- Author, assign, exempt, and maintain Azure Policy definitions and initiatives for a governed scope.
- Create remediation tasks for modify or deployIfNotExists policies after the assignment identity has the required target-resource roles.
Prerequisites (2)
- Define the policy lifecycle, assignment scope, exclusions, exemptions, enforcement mode, and testing process.
- For modify or deployIfNotExists, configure a system-assigned or user-assigned managed identity and grant its required remediation roles separately.
Best practices (2)
- Test definitions and assignments at a narrow nonproduction scope before expanding them through the hierarchy.
- Separate policy authors, assignment approvers, exemption approvers, and remediation identities where practical.
Security considerations (3)
- A policy assignment can deny deployments, modify resource requests, deploy resources, or create widespread noncompliance across inherited scopes.
- The role can create exemptions and remediation tasks, but the policy assignment managed identity performs target-resource changes with its separately assigned roles.
- This is a broad governance role and must not be called least privilege for a single exemption or remediation task.
Assignment guidance
Assign to the central policy engineering team at the hierarchy branch it governs. Use narrow custom roles for exemption-only workflows, review managed-identity roles independently, and require staged rollout for broad assignments.
Related roles (2)
- Policy Insights Data Writer (Preview): Preview component-compliance event writer, not a policy author role.
- Managed Identity Operator: May be required when attaching a user-assigned identity to a policy assignment; target remediation roles remain separate.
Editorial sources (7)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- What is Azure Policy? →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Azure Policy assignment structure →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.
- Remediate non-compliant resources with Azure Policy →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.