Azure Management and governance built-in role

SRE Agent Administrator

Provides full user control of an Azure SRE Agent, including chats, custom agents, knowledge, connectors, response plans, managed resources, settings, run modes, approvals, command execution, and agent deletion. These user permissions are distinct from the separate Azure roles assigned to the agent's user-assigned managed identity.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: e79298df-d852-4c6d-84f9-5d13249d1e55

Control-plane actions (6)

Data-plane actions (4)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the SRE Agent resource. This determines what the user can do with that agent; resource-group and subscription roles assigned to the agent-managed identity separately determine what Azure resources the agent can inspect or change.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign on the agent resource only to trusted SRE leaders and incident commanders. Review the agent managed identity separately, keep Standard Users from approval duties, and audit approvals, configuration changes, and OBO use.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →