Azure Integration built-in role

App Configuration Contributor

Performs App Configuration resource management operations except purging a deleted store. This control-plane role has no DataActions, but its wildcard can list and regenerate store API keys, which can be used to access all store data outside the direct Microsoft Entra data-role boundary.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: fe86443c-f201-4fc4-9d2a-ac61149fbda0

Control-plane actions (5)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (1)

Assignable scopes (1)

Practical scope

Assign on an existing App Configuration store when one store is administered. Creating a store or recovering a deleted store requires the write permission at the containing resource group or subscription; reading deleted stores requires subscription scope because deleted stores exist outside resource groups.

Common use cases (3)

Prerequisites (3)

Best practices (3)

Security considerations (5)

Assignment guidance

Assign App Configuration Contributor directly on an existing store only to administrators approved to list and regenerate its API keys. Use a dedicated resource-group assignment only when the platform group must create or recover that store, and use subscription scope only for documented deleted-store discovery. Assign Data Reader or Data Owner separately to workload identities; this control-plane role is not a data-plane least-privilege substitute.

Related roles (3)

Editorial sources (9)

Official Microsoft Learn documentation →