Azure Management and governance built-in role

SRE Agent Administrator

Provides full user control of an Azure SRE Agent, including chats, custom agents, knowledge, connectors, response plans, managed resources, settings, run modes, approvals, command execution, and agent deletion. These user permissions are distinct from the separate Azure roles assigned to the agent's user-assigned managed identity.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: e79298df-d852-4c6d-84f9-5d13249d1e55

Control-plane actions (6)

Data-plane actions (4)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the SRE Agent resource. This determines what the user can do with that agent; resource-group and subscription roles assigned to the agent-managed identity separately determine what Azure resources the agent can inspect or change.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign on the agent resource only to trusted SRE leaders and incident commanders. Review the agent managed identity separately, keep Standard Users from approval duties, and audit approvals, configuration changes, and OBO use.

Related roles (2)

Common questions

When should I assign the SRE Agent Administrator Azure role?

Assign SRE Agent Administrator when you need to: Administer agent configuration, connectors, knowledge, response plans, managed resources, and incident workflows.; and Review and approve actions or authorize on-behalf-of operations when the agent managed identity lacks required resource permissions.. Practical scope: Assign on the SRE Agent resource. This determines what the user can do with that agent; resource-group and subscription roles assigned to the agent-managed identity separately determine what Azure resources the agent can inspect or change.

What permissions does the SRE Agent Administrator Azure role grant?

The role definition grants 10 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Insights/alertRules/read; Microsoft.App/agents/read; Microsoft.App/agents/*/read; Microsoft.App/agents/write; and Microsoft.App/agents/*/write. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the SRE Agent Administrator Azure role?

Key considerations when assigning SRE Agent Administrator: Administrators can approve agent actions, delete resources through approved workflows, change connectors and run modes, and stop or delete the agent.; and User-role authority does not itself grant resource access, but Administrator can authorize on-behalf-of use of the administrator's own Azure permissions when the managed identity lacks access.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →