Azure Management and governance built-in role

Service Group Contributor

Preview role that manages Service Groups and their relationships but excludes creating and deleting Azure role assignments. It uses broad control-plane Actions within the Service Groups provider hierarchy and has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 32e6a4ec-6095-4e37-b54b-12aa350ba81f

Control-plane actions (1)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (2)

Assignable scopes (1)

Practical scope

Assign under `/providers/Microsoft.Management/serviceGroups` at the service group whose lifecycle and relationships the principal owns. Parent Service Group access applies through connected child relationships; this is distinct from the management-group subscription hierarchy.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign to service portfolio maintainers at the service group they own. Use Reader for observation and Administrator only when conditioned role delegation is also required.

Related roles (2)

Common questions

When should I assign the Service Group Contributor Azure role?

Assign Service Group Contributor when you need to: Create, update, delete, and organize preview service groups and their connected relationships.; and Delegate service-group lifecycle administration without Service Group role assignment authority.. Practical scope: Assign under `/providers/Microsoft.Management/serviceGroups` at the service group whose lifecycle and relationships the principal owns. Parent Service Group access applies through connected child relationships; this is distinct from the management-group subscription hierarchy.

What permissions does the Service Group Contributor Azure role grant?

The role definition grants 1 combined control-plane and data-plane actions. Representative operations include: *. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Service Group Contributor Azure role?

Key considerations when assigning Service Group Contributor: Creating, deleting, or reconnecting service groups can change how services are organized and governed through the preview hierarchy.; and The role excludes role assignment writes and deletes and has no DataActions, but its lifecycle wildcard remains broad within the provider scope.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →