Azure Integration built-in role

Services Hub Operator

Creates and manages Microsoft Engage Center Connector resources and related Services Hub connector operations. The current On-Demand Assessment guidance identifies Services Hub Operator at connector-subscription scope as the least-privileged built-in role for connector creation; it contains control-plane Actions and no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 82200a5b-e217-47a5-b665-6d8765ee745b

Control-plane actions (12)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the subscription that hosts the Engage Center Connector because connector creation and Microsoft.ServicesHub resource-provider registration are subscription-level operations. Log Analytics, VM or Arc extension, and Azure Monitor permissions remain separate at their documented narrower scopes.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Services Hub Operator at the connector subscription to the assessment setup operator. Add Log Analytics Contributor on the workspace, Virtual Machine Contributor on the specific VM or Azure Connected Machine Resource Administrator on the specific Arc server, and Monitoring Contributor on the resource group only when those tasks are required.

Related roles (4)

Common questions

When should I assign the Services Hub Operator Azure role?

Assign Services Hub Operator when you need to: Create and manage an Engage Center Connector for On-Demand Assessments in one Azure subscription.; and Register Microsoft.ServicesHub where applicable and manage connector assessment operations without using general subscription Contributor for the connector task.. Practical scope: Assign at the subscription that hosts the Engage Center Connector because connector creation and Microsoft.ServicesHub resource-provider registration are subscription-level operations. Log Analytics, VM or Arc extension, and Azure Monitor permissions remain separate at their documented narrower scopes.

What permissions does the Services Hub Operator Azure role grant?

The role definition grants 12 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Resources/subscriptions/resourceGroups/read; Microsoft.Resources/subscriptions/read; Microsoft.Resources/deployments/*; Microsoft.ServicesHub/connectors/write; and Microsoft.ServicesHub/connectors/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Services Hub Operator Azure role?

Key considerations when assigning Services Hub Operator: The role can create, change, and delete Engage Center Connector resources and manage assessment-related connector operations across the subscription.; It does not by itself authorize access to Log Analytics data, VM or Arc extensions, or Azure Monitor data-collection resources; those companion assignments expand the effective workflow.; and Subscription scope reaches every Services Hub or Engage Center Connector resource in that subscription.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →