Azure Management and governance built-in role

Service Group Administrator

Preview role that manages all aspects of Azure Service Groups and relationships and is assigned by default to a user who creates a service group. It also creates and deletes role assignments, but an ABAC condition restricts delegation to the Service Group Administrator, Contributor, and Reader role definition IDs.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 4e50c84c-c78e-4e37-b47e-e60ffea0a775

Control-plane actions (3)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (2)

Conditions (1)

Assignable scopes (1)

Practical scope

The definition is assignable only under `/providers/Microsoft.Management/serviceGroups`, a tenant-level Service Groups provider hierarchy with one root service group. Access at a parent service group applies through connected child relationships; it is not an Azure management-group or subscription scope.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign at the specific service group to its governance administrator. Use root scope only for tenant service-group administrators, retain the condition, and use Contributor when role delegation is unnecessary.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →