Azure Management and governance built-in role

Support Request Contributor

Creates and manages Azure support requests and reads resource health and support information. It does not grant permission to change the affected resource or read workload data, but support cases can contain sensitive diagnostic and contact information.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: cfd33db0-3dd1-45e3-aa9d-cdbdf3b6f24e

Control-plane actions (3)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign at the subscription or resource group whose support cases the principal may manage. A parent assignment can expose and permit case management across all inherited child resources.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign to authorized support coordinators at the subscription or bounded resource group. Keep resource remediation roles separate and review attachments for sensitive data before upload.

Editorial sources (5)

Official Microsoft Learn documentation →