Azure Networking built-in role

CDN Endpoint Contributor

Manages Azure CDN endpoint resources under a profile without granting Azure RBAC access. The definition also grants operation-result, deployment, classic alert-rule, support-ticket, authorization-read, edge-node-read, and resource-group-read Actions. It has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 426e0c7f-0c7e-4658-b36f-ff54d6c29b45

Control-plane actions (8)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

A CDN endpoint is created under a named CDN profile. Assign the role at the endpoint, containing profile, or dedicated resource group needed for the task. At resource-group or broader scope, its deployment, alert, and support Actions apply to corresponding resources throughout that scope, not only to one endpoint.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign CDN Endpoint Contributor to principals responsible for a defined CDN endpoint under an approved profile. Prefer endpoint or profile scope, and approve the ancillary deployment, alert, and support permissions whenever a broader scope is used.

Related roles (2)

Editorial sources (5)

Official Microsoft Learn documentation →