Azure Integration built-in role
Services Hub Operator
Creates and manages Microsoft Engage Center Connector resources and related Services Hub connector operations. The current On-Demand Assessment guidance identifies Services Hub Operator at connector-subscription scope as the least-privileged built-in role for connector creation; it contains control-plane Actions and no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 82200a5b-e217-47a5-b665-6d8765ee745b
Control-plane actions (12)
Microsoft.Authorization/*/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/deployments/*Microsoft.ServicesHub/connectors/writeMicrosoft.ServicesHub/connectors/readMicrosoft.ServicesHub/connectors/deleteMicrosoft.ServicesHub/connectors/checkAssessmentEntitlement/actionMicrosoft.ServicesHub/connectors/*Microsoft.ServicesHub/*Microsoft.ServicesHub/supportOfferingEntitlement/readMicrosoft.ServicesHub/workspaces/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at the subscription that hosts the Engage Center Connector because connector creation and Microsoft.ServicesHub resource-provider registration are subscription-level operations. Log Analytics, VM or Arc extension, and Azure Monitor permissions remain separate at their documented narrower scopes.
Common use cases (2)
- Create and manage an Engage Center Connector for On-Demand Assessments in one Azure subscription.
- Register Microsoft.ServicesHub where applicable and manage connector assessment operations without using general subscription Contributor for the connector task.
Prerequisites (2)
- The subscription must be eligible for the support and assessment workflow and the target resource group, Log Analytics workspace, and assessment machine must be identified.
- Register Microsoft.Insights separately when required and grant the documented companion roles on the Log Analytics workspace, VM or Arc server, and monitoring resource group.
Best practices (3)
- Use Services Hub Operator at subscription scope only for connector operations and add each companion role at the narrowest resource scope.
- Do not replace Log Analytics Contributor, Virtual Machine Contributor, Azure Connected Machine Resource Administrator, or Monitoring Contributor with broader subscription Contributor when their narrower scope is available.
- Review connector, workspace, extension, and monitoring assignments together when an assessment is retired or moved.
Security considerations (3)
- The role can create, change, and delete Engage Center Connector resources and manage assessment-related connector operations across the subscription.
- It does not by itself authorize access to Log Analytics data, VM or Arc extensions, or Azure Monitor data-collection resources; those companion assignments expand the effective workflow.
- Subscription scope reaches every Services Hub or Engage Center Connector resource in that subscription.
Assignment guidance
Assign Services Hub Operator at the connector subscription to the assessment setup operator. Add Log Analytics Contributor on the workspace, Virtual Machine Contributor on the specific VM or Azure Connected Machine Resource Administrator on the specific Arc server, and Monitoring Contributor on the resource group only when those tasks are required.
Related roles (4)
- Log Analytics Contributor: The documented companion role for linking the connector to an existing Log Analytics workspace.
- Virtual Machine Contributor: The documented companion role on a specific Azure VM when the assessment extension must be managed there.
- Azure Connected Machine Resource Administrator: The documented companion role on a specific Arc-enabled server when its assessment extension must be managed.
- Monitoring Contributor: The documented companion role for creating data collection rules and endpoints in the assessment resource group.
Editorial sources (6)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Minimum Azure RBAC permissions for On-Demand Assessment setup →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.