Azure Hybrid + multicloud built-in role

Azure Stack HCI VM Contributor

Azure Stack HCI VM Contributor creates, changes, starts, stops, restarts, and deletes VMs and their attached resources and extensions, but cannot register the system, assign roles, or create shared logical networks, images, and storage paths. The role uses Azure control-plane Actions and has no DataActions; Azure Arc resource bridge and the Azure Local operator project those authorized operations to the on-premises instance.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 874d1c73-6003-4e60-a13a-cb31ea190a85

Control-plane actions (75)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the resource group containing the workload VMs and their attached resources. Broader subscription scope exposes every inherited Azure Local workload, while individual-resource assignments may not cover all dependent disks and network interfaces.

Common use cases (1)

Prerequisites (2)

Best practices (2)

Security considerations (1)

Assignment guidance

Assign Azure Stack HCI VM Contributor to the workload user, group, service principal, or managed identity on the narrowest resource group containing the intended Azure Local resources. Verify access and the bridge state, then remove or lower the assignment when the operational need ends.

Related roles (2)

Common questions

When should I assign the Azure Stack HCI VM Contributor Azure role?

Assign Azure Stack HCI VM Contributor when you need to: Give an application or VM operations team self-service lifecycle management for its Azure Local VMs and attached disks, network interfaces, and extensions without platform registration or role delegation.. Practical scope: Assign on the resource group containing the workload VMs and their attached resources. Broader subscription scope exposes every inherited Azure Local workload, while individual-resource assignments may not cover all dependent disks and network interfaces.

What permissions does the Azure Stack HCI VM Contributor Azure role grant?

The role definition grants 75 combined control-plane and data-plane actions. Representative operations include: Microsoft.AzureStackHCI/VirtualMachines/*; Microsoft.AzureStackHCI/virtualMachineInstances/*; Microsoft.AzureStackHCI/NetworkInterfaces/*; Microsoft.AzureStackHCI/VirtualHardDisks/*; Microsoft.AzureStackHCI/VirtualNetworks/Read; and Microsoft.AzureStackHCI/VirtualNetworks/join/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure Stack HCI VM Contributor Azure role?

Key considerations when assigning Azure Stack HCI VM Contributor: The role can create, reconfigure, power-cycle, and delete VMs and attached disks and network interfaces and can manage extensions, affecting workload availability and guest execution.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (8)

Official Microsoft Learn documentation →