Azure Management and governance built-in role
Service Group Contributor
Preview role that manages Service Groups and their relationships but excludes creating and deleting Azure role assignments. It uses broad control-plane Actions within the Service Groups provider hierarchy and has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 32e6a4ec-6095-4e37-b54b-12aa350ba81f
Control-plane actions (1)
*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (2)
Microsoft.Authorization/roleAssignments/writeMicrosoft.Authorization/roleAssignments/delete
Assignable scopes (1)
/providers/Microsoft.Management/serviceGroups
Practical scope
Assign under `/providers/Microsoft.Management/serviceGroups` at the service group whose lifecycle and relationships the principal owns. Parent Service Group access applies through connected child relationships; this is distinct from the management-group subscription hierarchy.
Common use cases (2)
- Create, update, delete, and organize preview service groups and their connected relationships.
- Delegate service-group lifecycle administration without Service Group role assignment authority.
Prerequisites (2)
- The Service Groups preview must be in use and the target parent service group must exist.
- A Service Group Administrator must grant the assignment because Contributor cannot manage role assignments.
Best practices (2)
- Assign at a specific service-group branch and reserve Administrator for principals that must delegate the three Service Group roles.
- Review preview limitations, relationship changes, and root placement before production use.
Security considerations (2)
- Creating, deleting, or reconnecting service groups can change how services are organized and governed through the preview hierarchy.
- The role excludes role assignment writes and deletes and has no DataActions, but its lifecycle wildcard remains broad within the provider scope.
Assignment guidance
Assign to service portfolio maintainers at the service group they own. Use Reader for observation and Administrator only when conditioned role delegation is also required.
Related roles (2)
- Service Group Administrator: Adds ABAC-conditioned delegation of the three Service Group roles.
- Service Group Reader: Read-only counterpart.
Editorial sources (5)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- What are Azure Service Groups? →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.