Azure Management and governance built-in role

Service Group Contributor

Preview role that manages Service Groups and their relationships but excludes creating and deleting Azure role assignments. It uses broad control-plane Actions within the Service Groups provider hierarchy and has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 32e6a4ec-6095-4e37-b54b-12aa350ba81f

Control-plane actions (1)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (2)

Assignable scopes (1)

Practical scope

Assign under `/providers/Microsoft.Management/serviceGroups` at the service group whose lifecycle and relationships the principal owns. Parent Service Group access applies through connected child relationships; this is distinct from the management-group subscription hierarchy.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign to service portfolio maintainers at the service group they own. Use Reader for observation and Administrator only when conditioned role delegation is also required.

Related roles (2)

Editorial sources (5)

Official Microsoft Learn documentation →