Azure Compute built-in role

Windows Admin Center Administrator Login

Allows administrator-level operating-system management through Windows Admin Center in the Azure portal for supported Windows Azure IaaS VMs. The built-in definition contains permissions for additional resource types, but this reviewed workflow does not claim those platforms without a direct current Microsoft Learn workflow source.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: a6333a3e-0164-44c3-b281-7a577aff287f

Control-plane actions (41)

Data-plane actions (4)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Because the role includes DataActions, Microsoft documents assignment at subscription, resource group, or resource scope, not management-group scope. Assign at the individual VM or tightly bounded resource group; child resources inherit access. Reader is also required at the VM resource level for the Azure portal Windows Admin Center experience.

Common use cases (2)

Prerequisites (4)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Reader and Windows Admin Center Administrator Login on the individual target resource to the approved administrator group. Install the extension through a separately authorized deployment identity, prefer private connectivity, and avoid broad resource-group or subscription assignment unless every inherited resource is intentionally administered.

Related roles (1)

Common questions

When should I assign the Windows Admin Center Administrator Login Azure role?

Assign Windows Admin Center Administrator Login when you need to: Manage certificates, devices, events, files, firewall, local users, PowerShell, registry, services, storage, updates, and other OS functions through Windows Admin Center in the Azure portal.; and Connect as an administrator to a supported Windows Azure VM without using a conventional RDP session.. Practical scope: Because the role includes DataActions, Microsoft documents assignment at subscription, resource group, or resource scope, not management-group scope. Assign at the individual VM or tightly bounded resource group; child resources inherit access. Reader is also required at the VM resource level for the Azure portal Windows Admin Center experience.

What permissions does the Windows Admin Center Administrator Login Azure role grant?

The role definition grants 45 combined control-plane and data-plane actions. Representative operations include: Microsoft.HybridCompute/machines/*/read; Microsoft.HybridCompute/machines/extensions/*; Microsoft.HybridCompute/machines/upgradeExtensions/action; Microsoft.HybridCompute/operations/read; Microsoft.Network/networkInterfaces/read; and Microsoft.Network/loadBalancers/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Windows Admin Center Administrator Login Azure role?

Key considerations when assigning Windows Admin Center Administrator Login: Windows Admin Center creates a virtual account in the guest administrators group and exposes powerful OS tools including PowerShell, registry, files, firewall, local users, and updates.; Portal traffic to Windows Admin Center uses HTTPS, while management inside the VM uses PowerShell and WMI over WinRM; protect both the network path and the administrator session.; and Owner or Contributor alone does not grant Windows Admin Center guest access, preserving a documented separation between resource control and OS administration.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →