---
title: How to define an Azure Limited Admin custom role
description: Hi all, After implementing the Governance policies and foundations described in“Deploying Azure resource policies” it is important to make sure the end-con
---

[Skip to the main content.](https://uptec.io/blog/how-to-define-an-azure-limited-admin-custom-role#main-content)

- [Privacy Policy](https://uptec.io/privacy-policy-1)
- [Modern Slavery](https://uptec.io/modern-slavery-statement)
- [Net Zero Pledge](https://uptec.io/en-us/net-zero)

[![Logo-Transparant](https://uptec.io/hs-fs/hubfs/Logo-Transparant.png?width=936&height=804&name=Logo-Transparant.png "Logo-Transparant")](https://uptec.io/)

[![Logo-Transparant](https://uptec.io/hs-fs/hubfs/Logo-Transparant.png?width=936&height=804&name=Logo-Transparant.png "Logo-Transparant")](https://uptec.io/)

- [Home](https://uptec.io)
- [Products](https://uptec.io/products)
- [Services](https://uptec.io/services)
- [About](https://uptec.io/about)
- [News & Insights](https://uptec.io/blog)
- [Contact Us](https://uptec.io/contact-us)
- [Careers](https://uptec.io/careers)

Search

Toggle Menu

Search

Toggle Menu

- [Home](https://uptec.io)
- [Products](https://uptec.io/products)
- [Services](https://uptec.io/services)
- [About](https://uptec.io/about)
- [News & Insights](https://uptec.io/blog)
- [Contact Us](https://uptec.io/contact-us)
- [Careers](https://uptec.io/careers)

[Facebook](https://uptec.io/blog/how-to-define-an-azure-limited-admin-custom-role#0) [Instagram](https://uptec.io/blog/how-to-define-an-azure-limited-admin-custom-role#0) [Linkedin](https://uptec.io/blog/how-to-define-an-azure-limited-admin-custom-role#0) [X](https://uptec.io/blog/how-to-define-an-azure-limited-admin-custom-role#0) [YouTube](https://uptec.io/blog/how-to-define-an-azure-limited-admin-custom-role#0) [Medium](https://uptec.io/blog/how-to-define-an-azure-limited-admin-custom-role#0)

 2 min read

# How to define an Azure Limited Admin custom role

[Admin](https://uptec.io/blog/author/admin) :  Dec 8, 2023, 1:32:00 PM

Hi all,

After implementing the Governance policies and foundations described in“[Deploying Azure resource policies](http://mscloud.be/deploying-azure-resource-policies/)” it is important to make sure the end-consumers will not be able to change or remove those policies. In the customer environment I’m currently working on we defined Azure Resource Policies to enforce tagging, naming conventions, allowed regions etc., but we also enforced some network and routing settings. We implemented a really secure routing and firewall environment with User Defined Routes, NSG’s, virtual appliances, auditing and tracking etc. So we need to make sure users are not able to delete or change those policies and governance settings. This can be done with Azure RBAC.

## Azure Role Based Access (RBAC)

Azure Role-based access control will allow the owners of a subscription to assign granular roles to other users who can manage specific resource scopes in their environment. RBAC allows the flexibility of owning one Azure subscription managed by the administrator account (service administrator role at a subscription level) and have multiple users invited to work under the same subscription but without any administrative rights for it. You can assign RBAC at 3 different levels:

- Subscription level
- Resource Group
- Resource

For an overview of all the built-in user roles have a look here: [https://docs.microsoft.com/en-us/azure/active-directory/role-based-access-built-in-roles](https://docs.microsoft.com/en-us/azure/active-directory/role-based-access-built-in-roles)

The challenge today in Azure Role based access is that it’s really difficult to allow a user to create and delete anything in Azure (as we want to encourage users to test and play and discover) but at the same time make sure our policies and networking settings cannot me modified. I call this the “Limited Admin” User Role.

The solution is to create a new Custom Role.

## Azure Custom Role

Create a custom role in Azure Role-Based Access Control (RBAC) if none of the built-in roles meet your specific access needs. Custom roles can be created using [Azure PowerShell](https://docs.microsoft.com/en-us/azure/active-directory/role-based-access-control-manage-access-powershell), [Azure Command-Line Interface](https://docs.microsoft.com/en-us/azure/active-directory/role-based-access-control-manage-access-azure-cli) (CLI), and the [REST API](https://docs.microsoft.com/en-us/azure/active-directory/role-based-access-control-manage-access-rest). Just like built-in roles, you can assign custom roles to users, groups, and applications at subscription, resource group, and resource scopes. Custom roles are stored in an Azure AD tenant and can be shared across subscriptions.

Each tenant can create up to 2000 custom roles but my recommendation is to limit this as much as you can to limit the custom roles sprawl.

A JSON template can be used as the source definition for the custom role. The following example creates a custom role that will ensure the user can create and delete everything he wants but not the pre-defined network settings, UDR’s, NSG’s etc.

Create a new file `C:\Temp\LimitedAdmin.json` . The Id should be set to `null` on initial role creation as a new ID is generated automatically. Change the subscriptionID to match yours.

 View the code on [Gist](https://gist.github.com/averkinderen/af43d9e4c5d434356c8a0d3d99c3cdbd).

 To add the role to the subscriptions, run the following PowerShell command:

```
Login-AzureRMAccount
New-AzureRmRoleDefinition -InputFile "C:\Temp\LimitedAdmin.json"
```

 Now login to the Azure Portal and you should see your newly created custom role:

![](https://uptec.io/hs-fs/hubfs/Imported_Blog_Media/limitedadmin-300x129.png?width=300&height=129&name=limitedadmin-300x129.png)

 and the custom permissions can be seen here:

![](https://uptec.io/hs-fs/hubfs/Imported_Blog_Media/permissions-300x194.png?width=300&height=194&name=permissions-300x194.png)

 We have now created a new Azure Limited Admin by creating a new custom role.

 Hope this helps,

 Alex

- [Tweet](https://twitter.com/share)

 1 min read

#### [How to use Azure CDN for WordPress](https://uptec.io/blog/how-to-use-azure-cdn-for-wordpress)

[Alexandre Verkinderen](https://uptec.io/blog/author/alexandre-verkinderen) : Dec 8, 2023, 1:32:00 PM

In this blogpost I will show you how you can use Azure CDN to improve the performance of your WordPress site. I’m running WordPress for my blog and...

[Read More](https://uptec.io/blog/how-to-use-azure-cdn-for-wordpress)

[![Publish the new Azure API Management Service Developer Portal behind an Application Gateway](https://uptec.io/hubfs/Imported_Blog_Media/2020-06-10-AzureAPI-vnet.png)](https://uptec.io/blog/publish-new-azure-apim-developer_portal)

 2 min read

#### [Publish the new Azure API Management Service Developer Portal behind an Application Gateway](https://uptec.io/blog/publish-new-azure-apim-developer_portal)

[Alexandre Verkinderen](https://uptec.io/blog/author/alexandre-verkinderen) : Dec 8, 2023, 1:32:00 PM

There are currently 2 developer portals for the Azure API Management service: a legacy portal and the new portal experience. We deployed our Azure...

[Read More](https://uptec.io/blog/publish-new-azure-apim-developer_portal)

 1 min read

#### [Enabling Azure Network Security Group (NSG) flow logging in bulk](https://uptec.io/blog/enabling-azure-network-security-group-nsg-flow-logging-in-bulk)

[Admin](https://uptec.io/blog/author/admin) : Dec 8, 2023, 1:32:00 PM

As we speak one of my customers is looking into using Azure Network Watcher for its network auditing and packet logging capabilities. Network...

[Read More](https://uptec.io/blog/enabling-azure-network-security-group-nsg-flow-logging-in-bulk)

##### Australia

Australia

77 Cinnamon Meander

Two Rocks,

WA 6037, Australia

ABN: 48 643 822 833

##### Europe

Europe

Margote

Wichelen 9260,

Belgium

##### New Zealand

New Zealand

Suite A Floor 8 Harbourview Building,

152 Quay Street

Auckland Central 1010, New Zealand 

NZBN: 9429051226893

##### About

About

Uptec acknowledges the Traditional Owners of Country throughout Australia and acknowledges their continuing connection to land, waters and community. We pay our respects to the people, the cultures and the Elders past and present.

 

 

© 2026 Uptec Pty Ltd

[Linkedin](https://au.linkedin.com/company/uptecio) 

Return to top

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Admin",
    "url" : "https://uptec.io/blog/author/admin"
  },
  "dateModified" : "2024-12-08T02:36:24.603Z",
  "datePublished" : "2023-12-08T02:32:00.000Z",
  "headline" : "How to define an Azure Limited Admin custom role",
  "mainEntityOfPage" : {
    "@id" : "https://uptec.io/blog/how-to-define-an-azure-limited-admin-custom-role",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://uptec.io/hubfs/Logo.jpg"
    }
  }
}
```