Azure Security built-in role

Security Manager (Legacy)

Security Manager (Legacy) is a legacy Azure role. Microsoft states, "This is a legacy role. Please use Security Administrator instead." Its retained definition broadly manages Microsoft.Security resources, classic metric alerts, deployments, and support tickets and can write classic virtual machines, while exposing no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: e3d13bf0-dd5a-482e-ba6b-9b8433878d10

Control-plane actions (10)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Existing assignments apply at the selected Azure scope and are inherited by child scopes. Because the role combines broad security management with classic-compute authority, inventory every inherited assignment before replacing it with current roles at the narrowest supported scope.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Do not assign Security Manager (Legacy) for new work. For each existing assignment, map current Defender for Cloud duties to Security Admin, map any genuine classic-compute duty separately, test the replacement at the same or narrower scope, and remove the Legacy assignment.

Related roles (1)

Common questions

When should I assign the Security Manager (Legacy) Azure role?

Assign Security Manager (Legacy) when you need to: Temporarily support an existing legacy assignment while its actual Defender for Cloud and classic-compute duties are inventoried.; and Perform a controlled migration from Security Manager (Legacy) to current security and workload-specific roles without interrupting a remaining classic dependency.. Practical scope: Existing assignments apply at the selected Azure scope and are inherited by child scopes. Because the role combines broad security management with classic-compute authority, inventory every inherited assignment before replacing it with current roles at the narrowest supported scope.

What permissions does the Security Manager (Legacy) Azure role grant?

The role definition grants 10 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.ClassicCompute/*/read; Microsoft.ClassicCompute/virtualMachines/*/write; Microsoft.ClassicNetwork/*/read; Microsoft.Insights/alertRules/*; and Microsoft.ResourceHealth/availabilityStatuses/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Security Manager (Legacy) Azure role?

Key considerations when assigning Security Manager (Legacy): The Microsoft.Security wildcard can change broad security configuration, alerts, policies, and components throughout the assigned scope.; Classic virtual-machine write authority extends beyond read-only security posture and can alter legacy workloads.; and The role also changes classic metric alerts, deployments, and support tickets; retaining it after replacement creates duplicate and potentially broader cumulative access.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →