Azure Management roles and permissions
Cloud Commander will be decommissioned and stop functioning on May 13, 2026. You can use the product until that date.
Review and update workflows to remove any dependencies before the product is decommissioned.
Support, bug fixes, and security patches will be available until April 13, 2026.
| Role | Permission | Description |
|---|---|---|
| Azure Management Resource Admin Can run all operations on Azure Management resources. |
azure.alert.read | For all customers in the user's defined scope, the user can:
|
| azure.resource.read | ||
| azure.resource.readbasic | ||
| azure.virtualmachine.deallocate | ||
| azure.virtualmachine.restart | ||
| azure.virtualmachine.start | ||
| azure.virtualmachine.stop | ||
| azure.vm.read | ||
| azure.vm.readbasic | ||
| azuremgmt.error.read | ||
| azuremgmt.integration.read | ||
| azuremgmt.operation.read | ||
| azuremgmt.subscription.read | ||
| azuremgmt.subscription.write | ||
| azuremgmt.user.read | ||
| Azure Management Resource Reader
Can view all Azure Management resources & alerts. |
azure.alert.read | For all customers in the user's defined scope, the user can:
|
| azure.resource.read | ||
| azure.resource.readbasic | ||
| azure.vm.read | ||
| azure.vm.readbasic | ||
| azuremgmt.error.read | ||
| azuremgmt.integration.read | ||
| azuremgmt.subscription.read | ||
| azuremgmt.user.read | ||
| Azure Management Resource Writer Can run start, stop, and restart operation on Azure Management resources. |
azure.alert.read | For all customers in the user's defined scope, the user can:
|
| azure.resource.read | ||
| azure.resource.readbasic | ||
| azure.virtualmachine.restart | ||
| azure.virtualmachine.start | ||
| azure.virtualmachine.stop | ||
| azure.vm.read | ||
| azure.vm.readbasic | ||
| azuremgmt.error.read | ||
| azuremgmt.integration.read | ||
| azuremgmt.operation.read | ||
| azuremgmt.subscription.read | ||
| azuremgmt.subscription.write | ||
| azuremgmt.user.read |
Related articles
Updated: Jan 09, 2026
