Azure Security built-in role

Security Assessment Contributor

Writes Microsoft Defender for Cloud assessment results on resources and grants no other Actions or DataActions. The assessment API records a status such as Healthy, Unhealthy, or NotApplicable for predefined assessment metadata; this role does not remediate or manage the assessed resource.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 612c2aa1-cb24-443b-ac28-3ab7272de6f5

Control-plane actions (1)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign to the scanner, partner integration, or assessment-publishing identity on the exact resource set it evaluates. A resource-group, subscription, or management-group assignment is inherited and allows assessment writes on all child resources, so scope should follow the integration inventory rather than convenience.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Security Assessment Contributor to the dedicated assessment-publishing identity at the resource group or narrower boundary it scans. Predefine and validate assessment metadata, monitor every write, and grant separate roles only if the integration has an independently approved remediation responsibility.

Editorial sources (5)

Official Microsoft Learn documentation →