Azure Management and governance built-in role
SRE Agent Administrator
Provides full user control of an Azure SRE Agent, including chats, custom agents, knowledge, connectors, response plans, managed resources, settings, run modes, approvals, command execution, and agent deletion. These user permissions are distinct from the separate Azure roles assigned to the agent's user-assigned managed identity.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: e79298df-d852-4c6d-84f9-5d13249d1e55
Control-plane actions (6)
Microsoft.Authorization/*/readMicrosoft.Insights/alertRules/readMicrosoft.App/agents/readMicrosoft.App/agents/*/readMicrosoft.App/agents/writeMicrosoft.App/agents/*/write
Data-plane actions (4)
Microsoft.App/agents/*/readMicrosoft.App/agents/*/writeMicrosoft.App/agents/*/deleteMicrosoft.App/agents/threads/approve/action
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the SRE Agent resource. This determines what the user can do with that agent; resource-group and subscription roles assigned to the agent-managed identity separately determine what Azure resources the agent can inspect or change.
Common use cases (2)
- Administer agent configuration, connectors, knowledge, response plans, managed resources, and incident workflows.
- Review and approve actions or authorize on-behalf-of operations when the agent managed identity lacks required resource permissions.
Prerequisites (2)
- An Azure SRE Agent must exist and the administrator must understand its managed-resource scope, run modes, connectors, and managed-identity access.
- Only a work or school Microsoft Entra account can authorize the documented on-behalf-of flow.
Best practices (2)
- Limit Administrator to incident commanders and SRE or cloud administrators; use Standard User for investigation and Reader for observation.
- Start the agent managed identity with read access and grant specific write roles at resource-group scope only after review.
Security considerations (2)
- Administrators can approve agent actions, delete resources through approved workflows, change connectors and run modes, and stop or delete the agent.
- User-role authority does not itself grant resource access, but Administrator can authorize on-behalf-of use of the administrator's own Azure permissions when the managed identity lacks access.
Assignment guidance
Assign on the agent resource only to trusted SRE leaders and incident commanders. Review the agent managed identity separately, keep Standard Users from approval duties, and audit approvals, configuration changes, and OBO use.
Related roles (2)
- SRE Agent Standard User: Interacts with the agent and runs diagnostics but cannot approve actions or administer configuration.
- SRE Agent Reader: Read-only visibility into agent data.
Editorial sources (6)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- User roles and permissions in Azure SRE Agent →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Agent permissions in Azure SRE Agent →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.