Azure Compute built-in role
Virtual Machine Contributor
Broadly manages Azure virtual machines, scale sets, cloud services, availability resources, disks, network interfaces, VM extensions, Run Command, backup integration, SQL VM resources, serial console, and related deployments. It does not assign Azure RBAC roles and does not automatically grant guest sign-in, but it is not a least-privilege default.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 9980e02c-c2be-4d73-94e8-173b1dc7cf3c
Control-plane actions (45)
Microsoft.Authorization/*/readMicrosoft.Compute/availabilitySets/*Microsoft.Compute/locations/*Microsoft.Compute/virtualMachines/*Microsoft.Compute/virtualMachineScaleSets/*Microsoft.Compute/cloudServices/*Microsoft.Compute/disks/writeMicrosoft.Compute/disks/readMicrosoft.Compute/disks/deleteMicrosoft.Compute/hostgroups/writeMicrosoft.Compute/hostgroups/hosts/writeMicrosoft.DevTestLab/schedules/*Microsoft.Insights/alertRules/*Microsoft.Network/applicationGateways/backendAddressPools/join/actionMicrosoft.Network/loadBalancers/backendAddressPools/join/actionMicrosoft.Network/loadBalancers/inboundNatPools/join/actionMicrosoft.Network/loadBalancers/inboundNatRules/join/actionMicrosoft.Network/loadBalancers/probes/join/actionMicrosoft.Network/loadBalancers/readMicrosoft.Network/locations/*Microsoft.Network/networkInterfaces/*Microsoft.Network/networkSecurityGroups/join/actionMicrosoft.Network/networkSecurityGroups/readMicrosoft.Network/publicIPAddresses/join/actionMicrosoft.Network/publicIPAddresses/readMicrosoft.Network/virtualNetworks/readMicrosoft.Network/virtualNetworks/subnets/join/actionMicrosoft.RecoveryServices/locations/*Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/writeMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/*/readMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/readMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/writeMicrosoft.RecoveryServices/Vaults/backupPolicies/readMicrosoft.RecoveryServices/Vaults/backupPolicies/writeMicrosoft.RecoveryServices/Vaults/readMicrosoft.RecoveryServices/Vaults/usages/readMicrosoft.RecoveryServices/Vaults/writeMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.SerialConsole/serialPorts/connect/actionMicrosoft.SqlVirtualMachine/*Microsoft.Storage/storageAccounts/listKeys/actionMicrosoft.Storage/storageAccounts/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at a VM for one machine or at a dedicated VM resource group for an intentionally managed fleet; parent assignments are inherited. Its published permissions are control-plane Actions with no DataActions, yet extensions, password reset, Run Command, serial console, storage-key listing, and VM lifecycle operations can affect or expose guest workloads.
Common use cases (2)
- Operate the full lifecycle of an approved VM or scale-set estate, including disks, extensions, monitoring alerts, backup configuration, and supporting network interfaces.
- Run trusted deployment automation that must create, resize, start, stop, update, or delete VMs and execute guest configuration through extensions or Run Command.
Prerequisites (3)
- Identify the VM, disk, network, image, storage, backup, identity, quota, and availability resources required by the deployment.
- Grant separate network or storage management where the workflow must modify resources beyond the joins, reads, NIC operations, and storage-key access in this definition.
- Grant VM login roles separately when interactive guest access is required.
Best practices (3)
- Use narrower lifecycle, power, reader, login, or service-specific roles when they meet the task.
- Scope to the individual VM or dedicated resource group and use infrastructure as code, monitoring, backups, encryption, and resource locks where appropriate.
- Restrict and audit Run Command, VM extensions, serial console, password reset, and storage-key operations as privileged guest-impacting paths.
Security considerations (3)
- Action Run Command executes scripts under the System account on Windows or root on Linux. Managed Run Command can specify a customer-selected user; both variants remain privileged guest-execution paths.
- The role can delete VMs and disks, alter network interfaces, connect to serial console, list storage account keys, and change backup resources.
- No DataActions are present and VM login is separate, but control-plane execution and credential-recovery paths can provide effective control over guest data and operating systems.
Assignment guidance
Assign Virtual Machine Contributor only to trusted VM platform operators or deployment automation at the smallest VM or dedicated resource-group scope. Grant network, storage, identity attachment, and guest-login access separately, and choose narrower roles for power, sign-in, or read-only tasks.
Related roles (3)
- Virtual Machine Administrator Login: Microsoft documents guest administrator sign-in as a separate role; VM Contributor does not automatically grant it.
- Virtual Machine User Login: Microsoft documents regular guest sign-in as a separate role; VM Contributor does not automatically grant it.
- Network Contributor: Microsoft documents this separate role as useful for full network management beyond the network permissions bundled with VM Contributor.
Editorial sources (13)
- Azure built-in roles for Compute →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Run a Linux virtual machine on Azure →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Run scripts in a Windows or Linux virtual machine with Run Command →
Supports: Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Run scripts in a Windows VM using action Run Commands →
Supports: Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Run scripts in a Linux VM using action Run Commands →
Supports: Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Run scripts in a Windows VM using managed Run Commands →
Supports: Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Run scripts in a Linux VM using managed Run Commands →
Supports: Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Manage backups with Azure role-based access control →
Supports: Security considerations. Retrieved 2026-07-16.
- Sign in to a Linux virtual machine using Microsoft Entra ID and OpenSSH →
Supports: Related roles. Retrieved 2026-07-16.
- Sign in to a Windows virtual machine using Microsoft Entra ID →
Supports: Related roles. Retrieved 2026-07-16.