Azure Management and governance built-in role
Scheduled Patching Contributor
Creates and manages Azure Maintenance configurations with `InGuestPatch` scope and their machine assignments for scheduled patching. It is control-plane authority with no DataActions, but configuration assignments cause operating-system update installation on Azure VMs or Arc-enabled servers.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: cd08ab90-6b14-449c-ad9a-8f8e549482c6
Control-plane actions (14)
Microsoft.Maintenance/maintenanceConfigurations/readMicrosoft.Maintenance/maintenanceConfigurations/writeMicrosoft.Maintenance/maintenanceConfigurations/deleteMicrosoft.Maintenance/configurationAssignments/readMicrosoft.Maintenance/configurationAssignments/writeMicrosoft.Maintenance/configurationAssignments/deleteMicrosoft.Maintenance/configurationAssignments/maintenanceScope/InGuestPatch/readMicrosoft.Maintenance/configurationAssignments/maintenanceScope/InGuestPatch/writeMicrosoft.Maintenance/configurationAssignments/maintenanceScope/InGuestPatch/deleteMicrosoft.Maintenance/maintenanceConfigurations/maintenanceScope/InGuestPatch/readMicrosoft.Maintenance/maintenanceConfigurations/maintenanceScope/InGuestPatch/writeMicrosoft.Maintenance/maintenanceConfigurations/maintenanceScope/InGuestPatch/deleteMicrosoft.Maintenance/applyUpdates/readMicrosoft.Maintenance/updates/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign at the maintenance-configuration resource group and the machine or dynamic-scope boundaries required by the schedule. Broad scope can schedule patching across many subscriptions, resource groups, or machines.
Common use cases (2)
- Create recurring maintenance windows and assign Azure or Arc-enabled machines for scheduled guest patching.
- Manage static or dynamic scope assignments for an Azure Update Manager maintenance configuration.
Prerequisites (2)
- Machines must meet Azure Update Manager and scheduled-patching prerequisites and use a supported patch orchestration mode.
- Define maintenance windows, classifications, reboot behavior, scope, and the user-assigned managed identity needed for cross-subscription dynamic scoping where documented.
Best practices (2)
- Pilot schedules on nonproduction machines, align maintenance windows with workload owners, and monitor update results.
- Use separate maintenance configurations for different risk and availability groups and keep dynamic-scope filters narrowly defined.
Security considerations (2)
- Scheduled patches and reboots can disrupt workloads, while missing or overly broad assignments can leave systems unpatched or restart unintended machines.
- The role has no DataActions, but maintenance configuration and assignment changes have direct operating-system availability impact.
Assignment guidance
Assign to patch orchestration administrators at the maintenance configuration and intended machine scopes. Grant any required user-assigned identity access separately, test dynamic filters, and do not use broad scope without explicit fleet ownership.
Editorial sources (6)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Roles and permissions in Azure Update Manager →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Schedule recurring updates for machines using Azure Update Manager →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.