Azure Privileged built-in role
User Access Administrator
Manages user access to Azure resources through the broader Microsoft.Authorization permission set. It can create role assignments, including Owner assignments, and reads control-plane information for all Azure resource types.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 18d7d88d-d35e-4fb5-a5c3-7773c20a72d9
Control-plane actions (3)
*/readMicrosoft.Authorization/*Microsoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The built-in definition is available throughout the Azure hierarchy. An assignment applies at the selected scope and inherited child scopes. A Microsoft Entra Global Administrator can temporarily elevate to this Azure role at root scope, but Microsoft Entra roles and Azure roles otherwise remain separate. The role has no DataActions.
Common use cases (2)
- Manage Azure resource access when the required authorization work is broader than role-assignment create and delete operations alone.
- Temporarily regain or delegate Azure subscription and management-group access after a Microsoft Entra Global Administrator explicitly elevates at root scope.
Prerequisites (2)
- Confirm that Role Based Access Control Administrator is insufficient before selecting this broader access-administration role.
- The administrator creating the assignment needs Microsoft.Authorization/roleAssignments/write at the target scope; root-scope elevation additionally requires the Microsoft Entra Global Administrator role.
Best practices (3)
- Use Role Based Access Control Administrator for ordinary Azure RBAC delegation because Microsoft documents it as the lower-permission option.
- Constrain role-assignment authority with conditions, keep the assignment scope narrow, and use eligible PIM access for human administrators where available.
- Remove root-scope elevated access as soon as the recovery or access task is complete.
Security considerations (3)
- The assignee can grant Owner to itself or others unless its assignment is constrained.
- Root-scope elevation reaches all subscriptions and management groups associated with the tenant and must be temporary.
- This Azure role does not grant Microsoft Entra directory administration, and Microsoft Entra roles do not normally grant Azure resource access.
Assignment guidance
Choose this role only for access-administration tasks that require its broader Microsoft.Authorization authority. For routine role delegation, prefer Role Based Access Control Administrator with conditions. Keep root-scope elevation temporary, remove it after use, and use PIM for eligible human access where available.
Related roles (2)
- Role Based Access Control Administrator: Lower-permission Azure RBAC delegation role and the preferred constrained-delegation starting point.
- Global Administrator: Separate Microsoft Entra role that can explicitly elevate to User Access Administrator at Azure root scope; it is not duplicated as an Azure role.
Editorial sources (8)
- Azure built-in roles for Privileged →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Description, Common use cases, Prerequisites, Security considerations. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Eligible and time-bound role assignments in Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Delegate Azure role assignment management to others with conditions →
Supports: Prerequisites, Best practices, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Azure roles, Microsoft Entra roles, and classic subscription administrator roles →
Supports: Practical scope, Security considerations, Related roles. Retrieved 2026-07-16.
- Elevate access to manage all Azure subscriptions and management groups →
Supports: Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.