Azure Security built-in role

Security Manager (Legacy)

Security Manager (Legacy) is a legacy Azure role. Microsoft states, "This is a legacy role. Please use Security Administrator instead." Its retained definition broadly manages Microsoft.Security resources, classic metric alerts, deployments, and support tickets and can write classic virtual machines, while exposing no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: e3d13bf0-dd5a-482e-ba6b-9b8433878d10

Control-plane actions (10)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Existing assignments apply at the selected Azure scope and are inherited by child scopes. Because the role combines broad security management with classic-compute authority, inventory every inherited assignment before replacing it with current roles at the narrowest supported scope.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Do not assign Security Manager (Legacy) for new work. For each existing assignment, map current Defender for Cloud duties to Security Admin, map any genuine classic-compute duty separately, test the replacement at the same or narrower scope, and remove the Legacy assignment.

Related roles (1)

Editorial sources (5)

Official Microsoft Learn documentation →