Azure Management and governance built-in role
Support Request Contributor
Creates and manages Azure support requests and reads resource health and support information. It does not grant permission to change the affected resource or read workload data, but support cases can contain sensitive diagnostic and contact information.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: cfd33db0-3dd1-45e3-aa9d-cdbdf3b6f24e
Control-plane actions (3)
Microsoft.Authorization/*/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign at the subscription or resource group whose support cases the principal may manage. A parent assignment can expose and permit case management across all inherited child resources.
Common use cases (2)
- Create a technical, billing, subscription-management, or service-limit support request for an authorized Azure scope.
- Add diagnostics, communicate with Microsoft support, change severity or contact details, and close an existing request.
Prerequisites (2)
- The principal must be authorized for the subscription and have an applicable support plan for technical cases.
- Collect the resource ID, issue details, time range, business impact, and sanitized diagnostics before submission.
Best practices (2)
- Assign to a support coordination group and use organizational escalation and severity criteria.
- Remove credentials, secrets, personal data, and unrelated customer content from attachments and case notes.
Security considerations (2)
- Support requests can expose architecture, logs, contact details, incident timelines, and diagnostic artifacts to Microsoft support participants.
- The role cannot modify the affected resource or grant access, but changing severity or case content can affect support response and disclosure.
Assignment guidance
Assign to authorized support coordinators at the subscription or bounded resource group. Keep resource remediation roles separate and review attachments for sensitive data before upload.
Editorial sources (5)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Manage an Azure support request →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.