Azure Security built-in role
Security Manager (Legacy)
Security Manager (Legacy) is a legacy Azure role. Microsoft states, "This is a legacy role. Please use Security Administrator instead." Its retained definition broadly manages Microsoft.Security resources, classic metric alerts, deployments, and support tickets and can write classic virtual machines, while exposing no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: e3d13bf0-dd5a-482e-ba6b-9b8433878d10
Control-plane actions (10)
Microsoft.Authorization/*/readMicrosoft.ClassicCompute/*/readMicrosoft.ClassicCompute/virtualMachines/*/writeMicrosoft.ClassicNetwork/*/readMicrosoft.Insights/alertRules/*Microsoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Security/*Microsoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Existing assignments apply at the selected Azure scope and are inherited by child scopes. Because the role combines broad security management with classic-compute authority, inventory every inherited assignment before replacing it with current roles at the narrowest supported scope.
Common use cases (2)
- Temporarily support an existing legacy assignment while its actual Defender for Cloud and classic-compute duties are inventoried.
- Perform a controlled migration from Security Manager (Legacy) to current security and workload-specific roles without interrupting a remaining classic dependency.
Prerequisites (3)
- Confirm that the assignment already exists for a legacy workload; do not select this role for a new deployment.
- Inventory Microsoft.Security administration, deployment, support, classic virtual-machine write, and classic-network read dependencies separately.
- The migration administrator needs Microsoft.Authorization/roleAssignments/write to add replacement roles and Microsoft.Authorization/roleAssignments/delete to remove the legacy assignment.
Best practices (3)
- Create no new Security Manager (Legacy) assignments and follow Microsoft's direction to use the current Security Administrator role for current security administration.
- Replace classic-compute authority with a current workload role only if a documented remaining dependency requires it.
- Validate effective access after migration, then remove the legacy role so permissions are not cumulative.
Security considerations (3)
- The Microsoft.Security wildcard can change broad security configuration, alerts, policies, and components throughout the assigned scope.
- Classic virtual-machine write authority extends beyond read-only security posture and can alter legacy workloads.
- The role also changes classic metric alerts, deployments, and support tickets; retaining it after replacement creates duplicate and potentially broader cumulative access.
Assignment guidance
Do not assign Security Manager (Legacy) for new work. For each existing assignment, map current Defender for Cloud duties to Security Admin, map any genuine classic-compute duty separately, test the replacement at the same or narrower scope, and remove the Legacy assignment.
Related roles (1)
- Security Admin: The legacy role definition explicitly directs customers to use Security Administrator instead; the current canonical Azure built-in role is Security Admin.
Editorial sources (5)
- Azure built-in roles for Security →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Remove Azure role assignments →
Supports: Prerequisites, Best practices, Assignment guidance. Retrieved 2026-07-16.