Azure Compute built-in role

Virtual Machine Administrator Login

Allows Microsoft Entra-authenticated sign-in to supported Azure virtual machines and Azure Arc-enabled servers with administrator privileges. It combines control-plane resource visibility with login and login-as-administrator DataActions; VM ownership or contribution alone does not provide this guest access.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 1c0163c0-47e6-4577-8991-ea5c82e286e4

Control-plane actions (7)

Data-plane actions (4)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role can be assigned at management group, subscription, resource group, or resource scope and is inherited by child VMs and Arc machines. Microsoft recommends a management group, subscription, or resource-group assignment rather than one assignment per VM to avoid role-assignment limits, but the chosen scope must not grant administrator login to unrelated machines.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Virtual Machine Administrator Login to a tightly controlled administrator group at the resource group or other deliberate machine-fleet boundary. Enable and test Microsoft Entra sign-in first, enforce applicable Conditional Access, prefer PIM for people, and use User Login for non-administrative access.

Related roles (2)

Editorial sources (8)

Official Microsoft Learn documentation →