Azure Hybrid + multicloud built-in role
Azure Stack HCI Administrator
Azure Stack HCI Administrator registers and fully administers the Azure Local instance, cluster, VMs, extensions, shared VM resources, and selected role assignments. The role uses Azure control-plane Actions and has no DataActions; Azure Arc resource bridge and the Azure Local operator project those authorized operations to the on-premises instance.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: bda0d508-adf1-4af0-9c28-88919fc3ae06
Control-plane actions (103)
Microsoft.AzureStackHCI/register/actionMicrosoft.AzureStackHCI/Unregister/ActionMicrosoft.AzureStackHCI/clusters/*Microsoft.AzureStackHCI/NetworkSecurityGroups/ReadMicrosoft.AzureStackHCI/NetworkSecurityGroups/SecurityRules/ReadMicrosoft.AzureStackHCI/NetworkSecurityGroups/WriteMicrosoft.AzureStackHCI/NetworkSecurityGroups/SecurityRules/WriteMicrosoft.AzureStackHCI/NetworkSecurityGroups/DeleteMicrosoft.AzureStackHCI/NetworkSecurityGroups/SecurityRules/DeleteMicrosoft.AzureStackHCI/NetworkSecurityGroups/join/actionMicrosoft.HybridCompute/register/actionMicrosoft.GuestConfiguration/register/actionMicrosoft.GuestConfiguration/guestConfigurationAssignments/readMicrosoft.Resources/subscriptions/resourceGroups/writeMicrosoft.Resources/subscriptions/resourceGroups/deleteMicrosoft.HybridConnectivity/register/actionMicrosoft.Authorization/roleAssignments/writeMicrosoft.Authorization/roleAssignments/deleteMicrosoft.Authorization/*/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/subscriptions/readMicrosoft.Management/managementGroups/readMicrosoft.Support/*Microsoft.AzureStackHCI/*Microsoft.AzureStackHCI/EdgeMachines/*Microsoft.AzureStackHCI/DevicePools/*Microsoft.Insights/AlertRules/WriteMicrosoft.Insights/AlertRules/DeleteMicrosoft.Insights/AlertRules/ReadMicrosoft.Insights/AlertRules/Activated/ActionMicrosoft.Insights/AlertRules/Resolved/ActionMicrosoft.Insights/AlertRules/Throttled/ActionMicrosoft.Insights/AlertRules/Incidents/ReadMicrosoft.Resources/subscriptions/resourcegroups/deployments/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/writeMicrosoft.Resources/subscriptions/resourcegroups/deployments/operations/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/operationstatuses/readMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/operationresults/readMicrosoft.HybridCompute/machines/readMicrosoft.HybridCompute/machines/writeMicrosoft.HybridCompute/machines/deleteMicrosoft.HybridCompute/machines/UpgradeExtensions/actionMicrosoft.HybridCompute/machines/assessPatches/actionMicrosoft.HybridCompute/machines/installPatches/actionMicrosoft.HybridCompute/machines/extensions/readMicrosoft.HybridCompute/machines/extensions/writeMicrosoft.HybridCompute/machines/extensions/deleteMicrosoft.HybridCompute/operations/readMicrosoft.HybridCompute/locations/operationresults/readMicrosoft.HybridCompute/locations/operationstatus/readMicrosoft.HybridCompute/machines/patchAssessmentResults/readMicrosoft.HybridCompute/machines/patchAssessmentResults/softwarePatches/readMicrosoft.HybridCompute/machines/patchInstallationResults/readMicrosoft.HybridCompute/machines/patchInstallationResults/softwarePatches/readMicrosoft.HybridCompute/locations/updateCenterOperationResults/readMicrosoft.HybridCompute/machines/hybridIdentityMetadata/readMicrosoft.HybridCompute/osType/agentVersions/readMicrosoft.HybridCompute/osType/agentVersions/latest/readMicrosoft.HybridCompute/machines/runcommands/readMicrosoft.HybridCompute/machines/runcommands/writeMicrosoft.HybridCompute/machines/runcommands/deleteMicrosoft.HybridCompute/machines/licenseProfiles/readMicrosoft.HybridCompute/machines/licenseProfiles/writeMicrosoft.HybridCompute/machines/licenseProfiles/deleteMicrosoft.HybridCompute/licenses/readMicrosoft.HybridCompute/licenses/writeMicrosoft.HybridCompute/licenses/deleteMicrosoft.ResourceConnector/register/actionMicrosoft.ResourceConnector/appliances/readMicrosoft.ResourceConnector/appliances/writeMicrosoft.ResourceConnector/appliances/deleteMicrosoft.ResourceConnector/locations/operationresults/readMicrosoft.ResourceConnector/locations/operationsstatus/readMicrosoft.ResourceConnector/appliances/listClusterUserCredential/actionMicrosoft.ResourceConnector/appliances/listKeys/actionMicrosoft.ResourceConnector/operations/readMicrosoft.ExtendedLocation/register/actionMicrosoft.ExtendedLocation/customLocations/readMicrosoft.ExtendedLocation/customLocations/deploy/actionMicrosoft.ExtendedLocation/customLocations/writeMicrosoft.ExtendedLocation/customLocations/deleteMicrosoft.EdgeMarketplace/offers/readMicrosoft.EdgeMarketplace/publishers/readMicrosoft.Kubernetes/register/actionMicrosoft.KubernetesConfiguration/register/actionMicrosoft.KubernetesConfiguration/extensions/writeMicrosoft.KubernetesConfiguration/extensions/readMicrosoft.KubernetesConfiguration/extensions/deleteMicrosoft.KubernetesConfiguration/extensions/operations/readMicrosoft.KubernetesConfiguration/namespaces/readMicrosoft.KubernetesConfiguration/operations/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.AzureStackHCI/StorageContainers/WriteMicrosoft.AzureStackHCI/StorageContainers/ReadMicrosoft.HybridContainerService/register/actionMicrosoft.HybridCompute/settings/writeMicrosoft.HybridCompute/settings/readMicrosoft.HybridCompute/gateways/readMicrosoft.HybridCompute/gateways/writeMicrosoft.HybridCompute/gateways/delete
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Conditions (1)
Condition version: 2.0
((!(ActionMatches{'Microsoft.Authorization/roleAssignments/write'})) OR (@Request[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals{f5819b54-e033-4d82-ac66-4fec3cbf3f4c, cd570a14-e51a-42ad-bac8-bafd67325302, b64e21ea-ac4e-4cdf-9dc9-5b892992bee7, 4b3fe76c-f777-4d24-a2d7-b027b0f7b273, 874d1c73-6003-4e60-a13a-cb31ea190a85,865ae368-6a45-4bd1-8fbf-0d5151f56fc1,7b1f81f9-4196-4058-8aae-762e593270df,4633458b-17de-408a-b874-0445c86b69e6,c99c945f-8bd1-4fb1-a903-01460aae6068, b86a8fe4-44ce-4948-aee5-eccb2c155cd7, a4417e6f-fecd-4de8-b567-7b0420556985})) AND ((!(ActionMatches{'Microsoft.Authorization/roleAssignments/delete'})) OR (@Resource[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals{f5819b54-e033-4d82-ac66-4fec3cbf3f4c, cd570a14-e51a-42ad-bac8-bafd67325302, b64e21ea-ac4e-4cdf-9dc9-5b892992bee7, 4b3fe76c-f777-4d24-a2d7-b027b0f7b273, 874d1c73-6003-4e60-a13a-cb31ea190a85,865ae368-6a45-4bd1-8fbf-0d5151f56fc1,7b1f81f9-4196-4058-8aae-762e593270df,4633458b-17de-408a-b874-0445c86b69e6,c99c945f-8bd1-4fb1-a903-01460aae6068, b86a8fe4-44ce-4948-aee5-eccb2c155cd7, a4417e6f-fecd-4de8-b567-7b0420556985}))
Assignable scopes (1)
/
Practical scope
Assign on the Azure Local instance resource group unless administration must span multiple instances. A subscription assignment inherits full cluster authority and constrained delegation to every Azure Local instance below it.
Common use cases (1)
- Give the central Azure Local platform team authority to register and administer the instance, create shared logical networks, images, and storage paths, and delegate the documented Azure Local and supporting service roles.
Prerequisites (2)
- The Azure Local instance must be deployed and registered with a connected Azure Arc resource bridge and custom location, and all VM-management entities must be in a supported common Azure region.
- The assigning principal needs Owner or User Access Administrator. The workload must have the required VM image, logical network, storage path, and resource group; same-subscription infrastructure and workloads avoid documented cross-subscription CLI limitations.
Best practices (2)
- Keep this role with the central platform group, delegate VM Contributor or VM Reader for workload teams, and verify the role-assignment condition before use.
- Prefer resource-group scope, use groups for recurring access, verify the assignment with Check access, and use time-bound activation for privileged administration.
Security considerations (1)
- The role can register or unregister Azure Local, manage clusters and resource groups, deploy extensions and run commands on Arc machines, and create or remove assignments for the role IDs allowed by its condition.
Assignment guidance
Assign Azure Stack HCI Administrator to the Azure Local platform team on the narrowest resource group containing the intended Azure Local resources. Verify access and the bridge state, then remove or lower the assignment when the operational need ends.
Related roles (2)
- Azure Stack HCI VM Contributor: Provides workload VM lifecycle management without system registration, shared-resource creation, or role delegation.
- Azure Stack HCI VM Reader: Provides VM and supporting-resource visibility without VM lifecycle changes.
Editorial sources (8)
- Azure built-in roles for Hybrid + multicloud - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Eligible and time-bound role assignments in Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Use Role-based Access Control to manage Azure Local VMs enabled by Azure Arc →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Review prerequisites for Azure Local VMs enabled by Azure Arc →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.