Azure Management and governance built-in role

Scheduled Patching Contributor

Creates and manages Azure Maintenance configurations with `InGuestPatch` scope and their machine assignments for scheduled patching. It is control-plane authority with no DataActions, but configuration assignments cause operating-system update installation on Azure VMs or Arc-enabled servers.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: cd08ab90-6b14-449c-ad9a-8f8e549482c6

Control-plane actions (14)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign at the maintenance-configuration resource group and the machine or dynamic-scope boundaries required by the schedule. Broad scope can schedule patching across many subscriptions, resource groups, or machines.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign to patch orchestration administrators at the maintenance configuration and intended machine scopes. Grant any required user-assigned identity access separately, test dynamic filters, and do not use broad scope without explicit fleet ownership.

Common questions

When should I assign the Scheduled Patching Contributor Azure role?

Assign Scheduled Patching Contributor when you need to: Create recurring maintenance windows and assign Azure or Arc-enabled machines for scheduled guest patching.; and Manage static or dynamic scope assignments for an Azure Update Manager maintenance configuration.. Practical scope: Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign at the maintenance-configuration resource group and the machine or dynamic-scope boundaries required by the schedule. Broad scope can schedule patching across many subscriptions, resource groups, or machines.

What permissions does the Scheduled Patching Contributor Azure role grant?

The role definition grants 14 combined control-plane and data-plane actions. Representative operations include: Microsoft.Maintenance/maintenanceConfigurations/read; Microsoft.Maintenance/maintenanceConfigurations/write; Microsoft.Maintenance/maintenanceConfigurations/delete; Microsoft.Maintenance/configurationAssignments/read; Microsoft.Maintenance/configurationAssignments/write; and Microsoft.Maintenance/configurationAssignments/delete. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Scheduled Patching Contributor Azure role?

Key considerations when assigning Scheduled Patching Contributor: Scheduled patches and reboots can disrupt workloads, while missing or overly broad assignments can leave systems unpatched or restart unintended machines.; and The role has no DataActions, but maintenance configuration and assignment changes have direct operating-system availability impact.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →