Azure Management and governance built-in role
Tag Contributor
Creates, updates, and deletes tags on Azure resources, resource groups, and subscriptions without granting access to manage the tagged entities themselves. It has no DataActions, but tag writes can affect governance, automation, reporting, and cost allocation that consume tag values.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 4a9ae827-6dc8-4573-8ac7-8239d42aa03f
Control-plane actions (8)
Microsoft.Authorization/*/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/subscriptions/resourceGroups/resources/readMicrosoft.Resources/subscriptions/resources/readMicrosoft.Resources/deployments/*Microsoft.Insights/alertRules/*Microsoft.Support/*Microsoft.Resources/tags/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign at the subscription, resource group, or resource whose tags the principal manages. Azure tags do not automatically inherit from resource groups or subscriptions, although Azure Policy and Cost Management tag inheritance can copy or apply values through separate mechanisms.
Common use cases (2)
- Maintain ownership, cost-center, environment, data-classification, or lifecycle tags without resource administration.
- Run controlled tagging automation across an approved subscription or resource-group boundary.
Prerequisites (2)
- Define approved tag names, allowed values, casing, ownership, and conflict-resolution rules.
- Review Azure Policy, automation, and Cost Management processes that interpret or inherit tags.
Best practices (2)
- Use a governed tag schema and policy enforcement rather than ad hoc values.
- Scope broad tagging automation carefully and test changes against billing, deployment, security, and lifecycle workflows.
Security considerations (2)
- Tag changes can alter cost allocation, inventory, policy evaluation inputs, automation selection, or operational ownership without changing the resource itself.
- Tags are stored as plain text and can be exposed through multiple interfaces; do not place secrets or sensitive personal data in tags.
Assignment guidance
Assign to governance automation or metadata stewards at the exact tagging boundary. Do not represent Tag Contributor as resource management access, and review systems that trust tag values before broad assignment.
Editorial sources (5)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Use tags to organize your Azure resources and management hierarchy →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.