Azure Management and governance built-in role

Tag Contributor

Creates, updates, and deletes tags on Azure resources, resource groups, and subscriptions without granting access to manage the tagged entities themselves. It has no DataActions, but tag writes can affect governance, automation, reporting, and cost allocation that consume tag values.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 4a9ae827-6dc8-4573-8ac7-8239d42aa03f

Control-plane actions (8)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign at the subscription, resource group, or resource whose tags the principal manages. Azure tags do not automatically inherit from resource groups or subscriptions, although Azure Policy and Cost Management tag inheritance can copy or apply values through separate mechanisms.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign to governance automation or metadata stewards at the exact tagging boundary. Do not represent Tag Contributor as resource management access, and review systems that trust tag values before broad assignment.

Editorial sources (5)

Official Microsoft Learn documentation →