Azure Compute built-in role

Windows 365 Network Interface Contributor

Allows the Windows 365 first-party service to create, update, delete, join, and inspect network interfaces and to manage deployments in the resource group associated with an Azure network connection. It is a service role with no DataActions, not a Windows 365 administrator or human network contributor role.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 1f135831-5bbe-4924-9016-264044c00788

Control-plane actions (15)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign to the Windows First Party App on the resource group associated with the Azure network connection. The role is inherited by network interfaces and deployments in that group. Its permissions are control-plane Actions only and do not manage the virtual network itself.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Windows 365 Network Interface Contributor to the Windows First Party App on the ANC resource group, together with the documented subscription Reader and VNet-level Windows 365 Network User assignments. Remove legacy Network Contributor only after health validation succeeds.

Related roles (1)

Editorial sources (6)

Official Microsoft Learn documentation →