Azure Compute built-in role
Windows 365 Network Interface Contributor
Allows the Windows 365 first-party service to create, update, delete, join, and inspect network interfaces and to manage deployments in the resource group associated with an Azure network connection. It is a service role with no DataActions, not a Windows 365 administrator or human network contributor role.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 1f135831-5bbe-4924-9016-264044c00788
Control-plane actions (15)
Microsoft.Resources/subscriptions/resourcegroups/readMicrosoft.Resources/deployments/readMicrosoft.Resources/deployments/writeMicrosoft.Resources/deployments/deleteMicrosoft.Resources/deployments/operations/readMicrosoft.Resources/deployments/operationstatuses/readMicrosoft.Network/locations/operations/readMicrosoft.Network/locations/operationResults/readMicrosoft.Network/locations/usages/readMicrosoft.Network/networkInterfaces/writeMicrosoft.Network/networkInterfaces/readMicrosoft.Network/networkInterfaces/deleteMicrosoft.Network/networkInterfaces/join/actionMicrosoft.Network/networkInterfaces/effectiveNetworkSecurityGroups/actionMicrosoft.Network/networkInterfaces/effectiveRouteTable/action
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign to the Windows First Party App on the resource group associated with the Azure network connection. The role is inherited by network interfaces and deployments in that group. Its permissions are control-plane Actions only and do not manage the virtual network itself.
Common use cases (2)
- Allow Windows 365 to provision and manage Cloud PC network interfaces in the ANC resource group.
- Replace the older broad Network Contributor assignment on the ANC resource group with the Windows 365-specific service role.
Prerequisites (2)
- Use a customer-provided Azure network connection; Microsoft-hosted-network Cloud PCs do not require this Azure resource setup.
- Grant Reader on the subscription and Windows 365 Network User on the associated virtual network to the Windows 365 first-party service as documented.
Best practices (3)
- Assign only to the Windows First Party App and only on the ANC resource group.
- Use the Windows 365-specific roles instead of legacy Network Contributor assignments and remove old assignments only after the new roles are present.
- Run the ANC health check after role changes and review service assignments when an ANC is deleted or replaced.
Security considerations (3)
- The Windows 365 service can create, change, and delete every network interface and deployment in the inherited resource-group scope.
- The role does not grant virtual-network or subnet join by itself; Windows 365 Network User is the separate VNet assignment.
- Assigning it to a human does not grant Cloud PC administration and needlessly exposes service-specific network operations.
Assignment guidance
Assign Windows 365 Network Interface Contributor to the Windows First Party App on the ANC resource group, together with the documented subscription Reader and VNet-level Windows 365 Network User assignments. Remove legacy Network Contributor only after health validation succeeds.
Related roles (1)
- Windows 365 Network User: Microsoft documents this companion service assignment on the virtual network so Windows 365 can join Cloud PC network interfaces to its subnets.
Editorial sources (6)
- Azure built-in roles for Compute →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Role-based access control for Windows 365 →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Windows 365 requirements →
Supports: Prerequisites, Best practices, Related roles. Retrieved 2026-07-16.