Azure Security built-in role
Security Assessment Contributor
Writes Microsoft Defender for Cloud assessment results on resources and grants no other Actions or DataActions. The assessment API records a status such as Healthy, Unhealthy, or NotApplicable for predefined assessment metadata; this role does not remediate or manage the assessed resource.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 612c2aa1-cb24-443b-ac28-3ab7272de6f5
Control-plane actions (1)
Microsoft.Security/assessments/write
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign to the scanner, partner integration, or assessment-publishing identity on the exact resource set it evaluates. A resource-group, subscription, or management-group assignment is inherited and allows assessment writes on all child resources, so scope should follow the integration inventory rather than convenience.
Common use cases (2)
- Allow a trusted security product or internal scanner to push customer-managed or verified-partner assessment results into Defender for Cloud.
- Update the health status and supporting assessment data for a predefined assessment type on approved Azure or connected resources.
Prerequisites (3)
- Predefine assessment metadata with the same assessment name before inserting results.
- Use a dedicated Microsoft Entra application or managed identity and validate the target resource IDs, assessment type, status schema, and partner data requirements.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at the target resource or parent scope.
Best practices (3)
- Assign only to the assessment publisher identity and scope it to the resources that integration actually scans.
- Validate status values, resource identifiers, metadata names, and partner provenance before publishing results.
- Monitor assessment writes and alert on unexpected volume, resources, assessment names, or health-state changes.
Security considerations (3)
- A compromised publisher can falsify Healthy, Unhealthy, or NotApplicable results and distort Defender for Cloud recommendations and posture reporting.
- The role cannot modify the assessed workload or other Defender configuration and has no DataActions.
- A broad inherited assignment lets one integration write assessment state across unrelated applications or business units.
Assignment guidance
Assign Security Assessment Contributor to the dedicated assessment-publishing identity at the resource group or narrower boundary it scans. Predefine and validate assessment metadata, monitor every write, and grant separate roles only if the integration has an independently approved remediation responsibility.
Editorial sources (5)
- Azure built-in roles for Security →
Supports: Description, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Assessments - Create Or Update →
Supports: Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.