Assign Azure roles using the Azure portal

Azure role-based access control (Azure RBAC) is the authorization system you use to manage access to Azure resources. To grant access, you assign roles to users, groups, service principals, or managed identities at a particular scope. This article describes how to assign roles using the Azure portal.

If you need to assign administrator roles in Azure Active Directory, see Assign Azure AD roles to users.


To assign Azure roles, you must have:

Step 1: Identify the needed scope

When you assign roles, you must specify a scope. Scope is the set of resources the access applies to. In Azure, you can specify a scope at four levels from broad to narrow: management group, subscription, resource group, and resource. For more information, see Understand scope.

Diagram that shows the scope levels for Azure RBAC.

  1. Sign in to the Azure portal.

  2. In the Search box at the top, search for the scope you want to grant access to. For example, search for Management groups, Subscriptions, Resource groups, or a specific resource.

  3. Click the specific resource for that scope.

    The following shows an example resource group.

    Screenshot of resource group overview page.

Step 2: Open the Add role assignment page

Access control (IAM) is the page that you typically use to assign roles to grant access to Azure resources. It's also known as identity and access management (IAM) and appears in several locations in the Azure portal.

  1. Click Access control (IAM).

    The following shows an example of the Access control (IAM) page for a resource group.

    Screenshot of Access control (IAM) page for a resource group.

  2. Click the Role assignments tab to view the role assignments at this scope.

  3. Click Add > Add role assignment.

    If you don't have permissions to assign roles, the Add role assignment option will be disabled.

    Screenshot of Add > Add role assignment menu.

    The Add role assignment page opens.

Step 3: Select the appropriate role

  1. On the Role tab, select a role that you want to use.

    You can search for a role by name or by description. You can also filter roles by type and category.

    Screenshot of Add role assignment page with Role tab.

  2. If you want to assign a privileged administrator role, select the Privileged administrator roles tab to select the role.

    Privileged administrator roles are roles that grant privileged administrator access, such as the ability to manage Azure resources or assign roles to other users. You should avoid assigning a privileged administrator role when a job function role can be assigned instead. If you must assign a privileged administrator role, use a narrow scope, such as resource group or resource. For more information, see Privileged administrator roles.

    Screenshot of Add role assignment page with Privileged administrator roles tab selected.

  3. In the Details column, click View to get more details about a role.

    Screenshot of View role details pane with Permissions tab.

  4. Click Next.

Step 4: Select who needs access

  1. On the Members tab, select User, group, or service principal to assign the selected role to one or more Azure AD users, groups, or service principals (applications).

    Screenshot of Add role assignment page with Members tab.

  2. Click Select members.

  3. Find and select the users, groups, or service principals.

    You can type in the Select box to search the directory for display name or email address.

    Screenshot of Select members pane.

  4. Click Select to add the users, groups, or service principals to the Members list.

  5. To assign the selected role to one or more managed identities, select Managed identity.

  6. Click Select members.

  7. In the Select managed identities pane, select whether the type is user-assigned managed identity or system-assigned managed identity.

  8. Find and select the managed identities.

    For system-assigned managed identities, you can select managed identities by Azure service instance.

    Screenshot of Select managed identities pane.

  9. Click Select to add the managed identities to the Members list.

  10. In the Description box enter an optional description for this role assignment.

    Later you can show this description in the role assignments list.

  11. Click Next.

Step 5: (Optional) Add condition (preview)

If you selected a role that supports conditions, a Conditions (optional) tab will appear and you have the option to add a condition to your role assignment. A condition is an additional check that you can optionally add to your role assignment to provide more fine-grained access control.

Currently, conditions can be added to built-in or custom role assignments that have storage blob data actions. These include the following built-in roles:

  1. Click Add condition if you want to further refine the role assignments based on storage blob attributes. For more information, see Add or edit Azure role assignment conditions.

    Screenshot of Add role assignment page with Add condition tab.

  2. Click Next.

Step 6: Assign role

  1. On the Review + assign tab, review the role assignment settings.

    Screenshot of Assign a role page with Review + assign tab.

  2. Click Review + assign to assign the role.

    After a few moments, the security principal is assigned the role at the selected scope.

    Screenshot of role assignment list after assigning role.

  3. If you don't see the description for the role assignment, click Edit columns to add the Description column.

Next steps