Azure Hybrid + multicloud built-in role

Azure Stack HCI Administrator

Azure Stack HCI Administrator registers and fully administers the Azure Local instance, cluster, VMs, extensions, shared VM resources, and selected role assignments. The role uses Azure control-plane Actions and has no DataActions; Azure Arc resource bridge and the Azure Local operator project those authorized operations to the on-premises instance.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: bda0d508-adf1-4af0-9c28-88919fc3ae06

Control-plane actions (103)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Conditions (1)

Assignable scopes (1)

Practical scope

Assign on the Azure Local instance resource group unless administration must span multiple instances. A subscription assignment inherits full cluster authority and constrained delegation to every Azure Local instance below it.

Common use cases (1)

Prerequisites (2)

Best practices (2)

Security considerations (1)

Assignment guidance

Assign Azure Stack HCI Administrator to the Azure Local platform team on the narrowest resource group containing the intended Azure Local resources. Verify access and the bridge state, then remove or lower the assignment when the operational need ends.

Related roles (2)

Editorial sources (8)

Official Microsoft Learn documentation →