Management layer used to create, configure and remove resources, as distinct from the data plane where they are used. Azure Resource Manager fills this role for Azure, and in AKS Azure operates the Kubernetes control plane on your behalf.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-900AI-200AZ-802DP-600DP-700
Each book explains Control plane in context, with comparison tables and the common traps.
Terms in this definition
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
- Data plane
Operations that act on what is inside a resource, for example the secrets, keys and certificates held in a vault; in Key Vault these are authorised through data roles or access policies and filtered by the Key Vault firewall.
- WHERE
Limits a SELECT, UPDATE or DELETE to just the rows meeting a condition. Omit it, and the statement hits every row.
- ARM
Short for Azure Resource Manager, the control plane Azure uses for deploying and managing resources.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- AKS
Short for Azure Kubernetes Service, a managed Kubernetes offering that gives full control of clusters and node pools. Scaling uses the cluster autoscaler and Horizontal Pod Autoscaler; user sign-in is not built in.
Related terms
- Azure AI Administrator
Built-in role meant for Azure Machine Learning and Foundry hubs only, where it holds every control plane permission over Azure AI and the services it relies on. Today's Foundry resources are governed by Foundry Owner or Foundry Account Owner instead.
- Azure Route Server
Managed service that peers over BGP with network virtual appliances in a VNet and installs the learned routes on the VMs. It works purely in the control plane, so traffic never passes through it.
- Foundry control plane and data plane
The two halves of Foundry's RBAC model. Control plane actions cover resource settings, networking, deployments and project creation, whereas data plane actions cover work inside a project such as building agents, running evaluations and uploading files.
- Foundry Owner
Built-in role combining control plane and data plane rights, so its holders can stand up resources and projects, look after models and also build within projects; it is among the most privileged Foundry roles.
- Kubelet identity
AKS nodes pull container images using this user-assigned managed identity, so AcrPull on the registry must be granted to it rather than to the control plane identity.
- Microsoft Agent 365
Control plane for AI agents, licensed per user, that brings Entra security controls like Conditional Access to agents. The agent inventory lives in its registry within the Microsoft 365 admin centre.
- simplified Supervisor
Lightweight Supervisor option for vSphere, quicker and cheaper to deploy because there is just one VM for the control plane, with one network interface, VM Service as its sole service, no load balancer, and full features available to add afterwards. Foundation Load Balancer in its single-NIC, one-arm layout is supported only with this option.
- vSphere Zone
Supervisor object tied to precisely one vSphere cluster and one Supervisor. It can be tagged to host the control plane, given to namespaces for workloads, or used for both, as combined workload models do.