Azure Management and governance built-in role

Service Group Administrator

Preview role that manages all aspects of Azure Service Groups and relationships and is assigned by default to a user who creates a service group. It also creates and deletes role assignments, but an ABAC condition restricts delegation to the Service Group Administrator, Contributor, and Reader role definition IDs.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 4e50c84c-c78e-4e37-b47e-e60ffea0a775

Control-plane actions (3)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (2)

Conditions (1)

Assignable scopes (1)

Practical scope

The definition is assignable only under `/providers/Microsoft.Management/serviceGroups`, a tenant-level Service Groups provider hierarchy with one root service group. Access at a parent service group applies through connected child relationships; it is not an Azure management-group or subscription scope.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign at the specific service group to its governance administrator. Use root scope only for tenant service-group administrators, retain the condition, and use Contributor when role delegation is unnecessary.

Related roles (2)

Common questions

When should I assign the Service Group Administrator Azure role?

Assign Service Group Administrator when you need to: Create and administer preview service groups and connect supported resources or groups through service relationships.; and Delegate one of the three Service Group roles while preserving the built-in role-definition condition.. Practical scope: The definition is assignable only under `/providers/Microsoft.Management/serviceGroups`, a tenant-level Service Groups provider hierarchy with one root service group. Access at a parent service group applies through connected child relationships; it is not an Azure management-group or subscription scope.

What permissions does the Service Group Administrator Azure role grant?

The role definition grants 3 combined control-plane and data-plane actions. Representative operations include: *; Microsoft.Authorization/roleAssignments/write; and Microsoft.Authorization/roleAssignments/delete. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Service Group Administrator Azure role?

Key considerations when assigning Service Group Administrator: The wildcard Actions grant broad control in the Service Groups provider hierarchy.; and The ABAC condition limits role assignment to three Service Group roles but does not limit which principal receives an allowed role; scope and membership governance remain essential.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →