Azure Compute built-in role

Windows Admin Center Administrator Login

Allows administrator-level operating-system management through Windows Admin Center in the Azure portal for supported Windows Azure IaaS VMs. The built-in definition contains permissions for additional resource types, but this reviewed workflow does not claim those platforms without a direct current Microsoft Learn workflow source.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: a6333a3e-0164-44c3-b281-7a577aff287f

Control-plane actions (41)

Data-plane actions (4)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Because the role includes DataActions, Microsoft documents assignment at subscription, resource group, or resource scope, not management-group scope. Assign at the individual VM or tightly bounded resource group; child resources inherit access. Reader is also required at the VM resource level for the Azure portal Windows Admin Center experience.

Common use cases (2)

Prerequisites (4)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Reader and Windows Admin Center Administrator Login on the individual target resource to the approved administrator group. Install the extension through a separately authorized deployment identity, prefer private connectivity, and avoid broad resource-group or subscription assignment unless every inherited resource is intentionally administered.

Related roles (1)

Editorial sources (5)

Official Microsoft Learn documentation →