Azure Security built-in role

Security Assessment Contributor

Writes Microsoft Defender for Cloud assessment results on resources and grants no other Actions or DataActions. The assessment API records a status such as Healthy, Unhealthy, or NotApplicable for predefined assessment metadata; this role does not remediate or manage the assessed resource.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 612c2aa1-cb24-443b-ac28-3ab7272de6f5

Control-plane actions (1)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign to the scanner, partner integration, or assessment-publishing identity on the exact resource set it evaluates. A resource-group, subscription, or management-group assignment is inherited and allows assessment writes on all child resources, so scope should follow the integration inventory rather than convenience.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Security Assessment Contributor to the dedicated assessment-publishing identity at the resource group or narrower boundary it scans. Predefine and validate assessment metadata, monitor every write, and grant separate roles only if the integration has an independently approved remediation responsibility.

Common questions

When should I assign the Security Assessment Contributor Azure role?

Assign Security Assessment Contributor when you need to: Allow a trusted security product or internal scanner to push customer-managed or verified-partner assessment results into Defender for Cloud.; and Update the health status and supporting assessment data for a predefined assessment type on approved Azure or connected resources.. Practical scope: Assign to the scanner, partner integration, or assessment-publishing identity on the exact resource set it evaluates. A resource-group, subscription, or management-group assignment is inherited and allows assessment writes on all child resources, so scope should follow the integration inventory rather than convenience.

What permissions does the Security Assessment Contributor Azure role grant?

The role definition grants 1 combined control-plane and data-plane actions. Representative operations include: Microsoft.Security/assessments/write. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Security Assessment Contributor Azure role?

Key considerations when assigning Security Assessment Contributor: A compromised publisher can falsify Healthy, Unhealthy, or NotApplicable results and distort Defender for Cloud recommendations and posture reporting.; The role cannot modify the assessed workload or other Defender configuration and has no DataActions.; and A broad inherited assignment lets one integration write assessment state across unrelated applications or business units.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →