Azure Databases built-in role

SQL Managed Instance Contributor

Broadly manages Azure SQL Managed Instances and the virtual networks, subnets, network security groups, route tables, failover groups, and deployments required by the service. It has no DataActions, cannot grant Azure RBAC access, and excludes changes to Microsoft Entra-only authentication.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 4939a1f6-9ae0-4e48-a1e0-f2cbe897382d

Control-plane actions (15)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (2)

Assignable scopes (1)

Practical scope

Microsoft documents subscription scope for general provisioning because the role manages the instance and required network resources. When the subnet is already delegated and prepared, a custom or narrower permission containing Microsoft.Sql/managedInstances/write can be sufficient. SQL data access remains separate database-engine authorization.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Use SQL Managed Instance Contributor for a trusted provisioning identity only when it must manage both the instance and required network infrastructure. Follow Microsoft subscription-scope guidance for general provisioning, but prefer a narrower custom role for an already delegated subnet and keep SQL data and security administration separate.

Related roles (1)

Editorial sources (6)

Official Microsoft Learn documentation →