Azure Management and governance built-in role

SRE Agent Standard User

Lets a user chat with Azure SRE Agent, start threads, run diagnostics, upload knowledge documents, and request actions, but not approve actions, delete resources, modify connectors or response plans, manage resource scope, or change agent settings. Agent execution still depends on its managed identity or an Administrator-approved on-behalf-of flow.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 2d84a65a-63b2-4343-bbb6-31105d857bc1

Control-plane actions (3)

Data-plane actions (10)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the SRE Agent resource. This controls user interaction with the agent, not the Azure resource groups the agent can access; those roles belong to the agent's user-assigned managed identity.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign to responders at the agent resource. Keep approval, connector, run-mode, settings, and managed-resource changes on Administrator, and manage the agent identity's resource access independently.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →