Azure Hybrid + multicloud built-in role
Azure Stack HCI VM Contributor
Azure Stack HCI VM Contributor creates, changes, starts, stops, restarts, and deletes VMs and their attached resources and extensions, but cannot register the system, assign roles, or create shared logical networks, images, and storage paths. The role uses Azure control-plane Actions and has no DataActions; Azure Arc resource bridge and the Azure Local operator project those authorized operations to the on-premises instance.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 874d1c73-6003-4e60-a13a-cb31ea190a85
Control-plane actions (75)
Microsoft.AzureStackHCI/VirtualMachines/*Microsoft.AzureStackHCI/virtualMachineInstances/*Microsoft.AzureStackHCI/NetworkInterfaces/*Microsoft.AzureStackHCI/VirtualHardDisks/*Microsoft.AzureStackHCI/VirtualNetworks/ReadMicrosoft.AzureStackHCI/VirtualNetworks/join/actionMicrosoft.AzureStackHCI/LogicalNetworks/ReadMicrosoft.AzureStackHCI/LogicalNetworks/join/actionMicrosoft.AzureStackHCI/GalleryImages/ReadMicrosoft.AzureStackHCI/GalleryImages/deploy/actionMicrosoft.AzureStackHCI/StorageContainers/ReadMicrosoft.AzureStackHCI/StorageContainers/deploy/actionMicrosoft.AzureStackHCI/MarketplaceGalleryImages/ReadMicrosoft.AzureStackHCI/MarketPlaceGalleryImages/deploy/actionMicrosoft.AzureStackHCI/Clusters/ReadMicrosoft.AzureStackHCI/Clusters/ArcSettings/ReadMicrosoft.AzureStackHCI/NetworkSecurityGroups/ReadMicrosoft.AzureStackHCI/NetworkSecurityGroups/SecurityRules/ReadMicrosoft.Insights/AlertRules/WriteMicrosoft.Insights/AlertRules/DeleteMicrosoft.Insights/AlertRules/ReadMicrosoft.Insights/AlertRules/Activated/ActionMicrosoft.Insights/AlertRules/Resolved/ActionMicrosoft.Insights/AlertRules/Throttled/ActionMicrosoft.Insights/AlertRules/Incidents/ReadMicrosoft.Resources/deployments/readMicrosoft.Resources/deployments/writeMicrosoft.Resources/deployments/deleteMicrosoft.Resources/deployments/cancel/actionMicrosoft.Resources/deployments/validate/actionMicrosoft.Resources/deployments/whatIf/actionMicrosoft.Resources/deployments/exportTemplate/actionMicrosoft.Resources/deployments/operations/readMicrosoft.Resources/deployments/operationstatuses/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/writeMicrosoft.Resources/subscriptions/resourcegroups/deployments/operations/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/operationstatuses/readMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Authorization/*/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/subscriptions/operationresults/readMicrosoft.HybridCompute/machines/readMicrosoft.HybridCompute/machines/writeMicrosoft.HybridCompute/machines/deleteMicrosoft.HybridCompute/machines/UpgradeExtensions/actionMicrosoft.HybridCompute/machines/assessPatches/actionMicrosoft.HybridCompute/machines/installPatches/actionMicrosoft.HybridCompute/machines/extensions/readMicrosoft.HybridCompute/machines/extensions/writeMicrosoft.HybridCompute/machines/extensions/deleteMicrosoft.HybridCompute/operations/readMicrosoft.HybridCompute/locations/operationresults/readMicrosoft.HybridCompute/locations/operationstatus/readMicrosoft.HybridCompute/machines/patchAssessmentResults/readMicrosoft.HybridCompute/machines/patchAssessmentResults/softwarePatches/readMicrosoft.HybridCompute/machines/patchInstallationResults/readMicrosoft.HybridCompute/machines/patchInstallationResults/softwarePatches/readMicrosoft.HybridCompute/locations/updateCenterOperationResults/readMicrosoft.HybridCompute/machines/hybridIdentityMetadata/readMicrosoft.HybridCompute/osType/agentVersions/readMicrosoft.HybridCompute/osType/agentVersions/latest/readMicrosoft.HybridCompute/machines/runcommands/readMicrosoft.HybridCompute/machines/runcommands/writeMicrosoft.HybridCompute/machines/runcommands/deleteMicrosoft.HybridCompute/machines/licenseProfiles/readMicrosoft.HybridCompute/machines/licenseProfiles/writeMicrosoft.HybridCompute/machines/licenseProfiles/deleteMicrosoft.HybridCompute/licenses/readMicrosoft.HybridCompute/licenses/writeMicrosoft.HybridCompute/licenses/deleteMicrosoft.ExtendedLocation/customLocations/ReadMicrosoft.ExtendedLocation/customLocations/deploy/actionMicrosoft.KubernetesConfiguration/extensions/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the resource group containing the workload VMs and their attached resources. Broader subscription scope exposes every inherited Azure Local workload, while individual-resource assignments may not cover all dependent disks and network interfaces.
Common use cases (1)
- Give an application or VM operations team self-service lifecycle management for its Azure Local VMs and attached disks, network interfaces, and extensions without platform registration or role delegation.
Prerequisites (2)
- The Azure Local instance must be deployed and registered with a connected Azure Arc resource bridge and custom location, and all VM-management entities must be in a supported common Azure region.
- The assigning principal needs Owner or User Access Administrator. The workload must have the required VM image, logical network, storage path, and resource group; same-subscription infrastructure and workloads avoid documented cross-subscription CLI limitations.
Best practices (2)
- Use VM Reader for inspection-only work and leave shared images, logical networks, and storage paths under the platform administrator.
- Prefer resource-group scope, use groups for recurring access, verify the assignment with Check access, and use time-bound activation for privileged administration.
Security considerations (1)
- The role can create, reconfigure, power-cycle, and delete VMs and attached disks and network interfaces and can manage extensions, affecting workload availability and guest execution.
Assignment guidance
Assign Azure Stack HCI VM Contributor to the workload user, group, service principal, or managed identity on the narrowest resource group containing the intended Azure Local resources. Verify access and the bridge state, then remove or lower the assignment when the operational need ends.
Related roles (2)
- Azure Stack HCI Administrator: Provides full Azure Local platform, shared-resource, VM, and constrained delegation authority.
- Azure Stack HCI VM Reader: Provides VM and supporting-resource visibility without VM lifecycle changes.
Editorial sources (8)
- Azure built-in roles for Hybrid + multicloud - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Eligible and time-bound role assignments in Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Use Role-based Access Control to manage Azure Local VMs enabled by Azure Arc →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Review prerequisites for Azure Local VMs enabled by Azure Arc →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.