last sync: 2025-Oct-30 18:22:48 UTC

Azure Migrate Owner

Azure BuiltIn RBAC Role definition

NameAzure Migrate Owner
Idfd8ea4d5-6509-4db0-bada-356ab233b4fa
DescriptionGrants full access to create and manage Azure Migrate projects including appliance-based discovery, creation of business case & assessment report and execution of migrations; Also grants ability to assign Azure Migrate specific roles in Azure RBAC.
CategoryNone
CreatedOn2025-09-08 16:26:58 UTC
UpdatedOn2025-10-20 15:12:57 UTC
Permissions summary Effective control plane and data plane operations: 1121 (unique operations)
•: 1
•action: 271
•delete: 136
•read: 503
•write: 210

Actions: 68
Resolved control plane operations from Actions: 1121
Effective control plane operations: 1121
•: 1
•action: 271
•delete: 136
•read: 503
•write: 210

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 16344

DataActions: 0
Resolved data plane operations: 0
Effective data plane operations: 0

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 4081
Actions
Operation Description
Microsoft.ApplicationMigration/*wildcarded / no description
Microsoft.Authorization/*/readwildcarded / no description
Microsoft.Authorization/locks/deleteDelete locks at the specified scope.
Microsoft.Authorization/locks/writeAdd locks at the specified scope.
Microsoft.Authorization/roleAssignments/delete conditionedDelete a role assignment at the specified scope.
Microsoft.Authorization/roleAssignments/write conditionedCreate a role assignment at the specified scope.
Microsoft.AzureArcData/register/actionRegister the subscription for Microsoft.AzureArcData
Microsoft.Compute/availabilitySets/readGet the properties of an availability set
Microsoft.Compute/availabilitySets/vmSizes/readList available sizes for creating or updating a virtual machine in the availability set
Microsoft.Compute/diskEncryptionSets/readGet the properties of a disk encryption set
Microsoft.Compute/disks/deleteDeletes the Disk
Microsoft.Compute/disks/readGet the properties of a Disk
Microsoft.Compute/disks/writeCreates a new Disk or updates an existing one
Microsoft.Compute/register/actionRegisters Subscription with Microsoft.Compute resource provider
Microsoft.Compute/skus/readGets the list of Microsoft.Compute SKUs available for your Subscription
Microsoft.Compute/virtualMachines/deleteDeletes the virtual machine
Microsoft.Compute/virtualMachines/readGet the properties of a virtual machine
Microsoft.Compute/virtualMachines/writeCreates a new virtual machine or updates an existing virtual machine
Microsoft.DataReplication/*/readwildcarded / no description
Microsoft.DataReplication/register/actionRegisters the subscription for the Microsoft.DataReplication resource provider
Microsoft.DataReplication/replicationVaults/writeUpdates any vault
Microsoft.DependencyMap/*wildcarded / no description
Microsoft.GuestConfiguration/register/actionRegisters the subscription for the Microsoft.GuestConfiguration resource provider.
Microsoft.HybridCompute/machines/deleteDeletes an Azure Arc machines
Microsoft.HybridCompute/machines/readRead any Azure Arc machines
Microsoft.HybridCompute/machines/writeWrites an Azure Arc machines
Microsoft.HybridCompute/register/actionRegisters the subscription for the Microsoft.HybridCompute Resource Provider
Microsoft.HybridConnectivity/register/actionRegister the subscription for Microsoft.HybridConnectivity
Microsoft.Insights/alertRules/*wildcarded / no description
Microsoft.KeyVault/checkNameAvailability/readChecks that a key vault name is valid and is not in use
Microsoft.KeyVault/register/actionRegisters a subscription
Microsoft.KeyVault/vaults/*wildcarded / no description
Microsoft.Migrate/*wildcarded / no description
Microsoft.MySQLDiscovery/*wildcarded / no description
Microsoft.Network/networkInterfaces/deleteDeletes a network interface
Microsoft.Network/networkInterfaces/readGets a network interface definition.
Microsoft.Network/networkInterfaces/writeCreates a network interface or updates an existing network interface.
Microsoft.Network/networkSecurityGroups/join/actionJoins a network security group. Not Alertable.
Microsoft.Network/privateDnsZones/A/writeCreate or update a record set of type ‘A’ within a Private DNS zone. The records specified will replace the current records in the record set.
Microsoft.Network/privateDnsZones/join/actionJoins a Private DNS Zone
Microsoft.Network/privateDnsZones/virtualNetworkLinks/writeCreate or update a Private DNS zone link to virtual network.
Microsoft.Network/privateDnsZones/writeCreate or update a Private DNS zone within a resource group. Note that this command cannot be used to create or update virtual network links or record sets within the zone.
Microsoft.Network/privateEndpoints/privateDnsZoneGroups/readGets a Private DNS Zone Group
Microsoft.Network/privateEndpoints/privateDnsZoneGroups/writePuts a Private DNS Zone Group
Microsoft.Network/privateEndpoints/readGets an private endpoint resource.
Microsoft.Network/privateEndpoints/writeCreates a new private endpoint, or updates an existing private endpoint.
Microsoft.Network/register/actionRegisters the subscription
Microsoft.Network/virtualNetworks/join/actionJoins a virtual network. Not Alertable.
Microsoft.Network/virtualNetworks/readGet the virtual network definition
Microsoft.Network/virtualNetworks/subnets/join/actionJoins a virtual network. Not Alertable.
Microsoft.Network/virtualNetworks/subnets/readGets a virtual network subnet definition
Microsoft.Network/virtualNetworks/subnets/writeCreates a virtual network subnet or updates an existing virtual network subnet
Microsoft.OffAzure/*wildcarded / no description
Microsoft.RecoveryServices/operations/readOperation returns the list of Operations for a Resource Provider
Microsoft.RecoveryServices/register/actionRegisters subscription for given Resource Provider
Microsoft.RecoveryServices/vaults/*wildcarded / no description
Microsoft.Resources/checkResourceName/actionCheck the resource name for validity.
Microsoft.Resources/deployments/*wildcarded / no description
Microsoft.Resources/deploymentScripts/readGets or lists deployment scripts
Microsoft.Resources/deploymentScripts/writeCreates or updates a deployment script
Microsoft.Resources/links/readGets or lists resource links.
Microsoft.Resources/links/writeCreates or updates a resource link.
Microsoft.Resources/subscriptions/locations/readGets the list of locations supported.
Microsoft.Resources/subscriptions/readGets the list of subscriptions.
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups.
Microsoft.Resources/subscriptions/resourceGroups/writeCreates or updates a resource group.
Microsoft.Storage/storageAccounts/*wildcarded / no description
Microsoft.Support/*wildcarded / no description
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in
BuiltIn Policy
none
History
Date/Time (UTC ymd) (i) Change Change detail
2025-10-23 17:22:49 add: Role fd8ea4d5-6509-4db0-bada-356ab233b4fa
JSON
api-version=2023-07-01-preview
Condition
    
    (
        (
            !
            (
                ActionMatches {
                'Microsoft.Authorization/roleAssignments/write'
                }
            )
        )
        OR
        (
            @Request[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals {
            7859c0b0-0bb9-4994-bd12-cd529af7d646 (Azure Migrate Decide and Plan Expert),
            1cfa4eac-9a23-481c-a793-bfb6958e836b (Azure Migrate Execute Expert),
            17d1049b-9a84-46fb-8f53-869881c3d3ab (Storage Account Contributor),
            ba92f5b4-2d11-453d-a403-e96b0029c9fe (Storage Blob Data Contributor),
            ba480ccd-6499-4709-b581-8f38bb215c63 (Azure Migrate Service Reader)
            }
        )
    )
    AND
    (
        (
            !
            (
                ActionMatches {
                'Microsoft.Authorization/roleAssignments/delete'
                }
            )
        )
        OR
        (
            @Resource[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals {
            7859c0b0-0bb9-4994-bd12-cd529af7d646 (Azure Migrate Decide and Plan Expert),
            1cfa4eac-9a23-481c-a793-bfb6958e836b (Azure Migrate Execute Expert),
            17d1049b-9a84-46fb-8f53-869881c3d3ab (Storage Account Contributor),
            ba92f5b4-2d11-453d-a403-e96b0029c9fe (Storage Blob Data Contributor),
            ba480ccd-6499-4709-b581-8f38bb215c63 (Azure Migrate Service Reader)
            }
        )
    )