Azure Compute built-in role

Windows 365 Network Interface Contributor

Allows the Windows 365 first-party service to create, update, delete, join, and inspect network interfaces and to manage deployments in the resource group associated with an Azure network connection. It is a service role with no DataActions, not a Windows 365 administrator or human network contributor role.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 1f135831-5bbe-4924-9016-264044c00788

Control-plane actions (15)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign to the Windows First Party App on the resource group associated with the Azure network connection. The role is inherited by network interfaces and deployments in that group. Its permissions are control-plane Actions only and do not manage the virtual network itself.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Windows 365 Network Interface Contributor to the Windows First Party App on the ANC resource group, together with the documented subscription Reader and VNet-level Windows 365 Network User assignments. Remove legacy Network Contributor only after health validation succeeds.

Related roles (1)

Common questions

When should I assign the Windows 365 Network Interface Contributor Azure role?

Assign Windows 365 Network Interface Contributor when you need to: Allow Windows 365 to provision and manage Cloud PC network interfaces in the ANC resource group.; and Replace the older broad Network Contributor assignment on the ANC resource group with the Windows 365-specific service role.. Practical scope: Assign to the Windows First Party App on the resource group associated with the Azure network connection. The role is inherited by network interfaces and deployments in that group. Its permissions are control-plane Actions only and do not manage the virtual network itself.

What permissions does the Windows 365 Network Interface Contributor Azure role grant?

The role definition grants 15 combined control-plane and data-plane actions. Representative operations include: Microsoft.Resources/subscriptions/resourcegroups/read; Microsoft.Resources/deployments/read; Microsoft.Resources/deployments/write; Microsoft.Resources/deployments/delete; Microsoft.Resources/deployments/operations/read; and Microsoft.Resources/deployments/operationstatuses/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Windows 365 Network Interface Contributor Azure role?

Key considerations when assigning Windows 365 Network Interface Contributor: The Windows 365 service can create, change, and delete every network interface and deployment in the inherited resource-group scope.; The role does not grant virtual-network or subnet join by itself; Windows 365 Network User is the separate VNet assignment.; and Assigning it to a human does not grant Cloud PC administration and needlessly exposes service-specific network operations.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →