The Managed Identity How-To guide (https://docs.microsoft.com/en-us/azure/cyclecloud/managed-identities) says to create a custom role. Consider the difference between this role and 'Contributor' (which we have verified also works, and removes a long step).