Azure Networking built-in role

CDN Endpoint Contributor

Manages Azure CDN endpoint resources under a profile without granting Azure RBAC access. The definition also grants operation-result, deployment, classic alert-rule, support-ticket, authorization-read, edge-node-read, and resource-group-read Actions. It has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 426e0c7f-0c7e-4658-b36f-ff54d6c29b45

Control-plane actions (8)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

A CDN endpoint is created under a named CDN profile. Assign the role at the endpoint, containing profile, or dedicated resource group needed for the task. At resource-group or broader scope, its deployment, alert, and support Actions apply to corresponding resources throughout that scope, not only to one endpoint.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign CDN Endpoint Contributor to principals responsible for a defined CDN endpoint under an approved profile. Prefer endpoint or profile scope, and approve the ancillary deployment, alert, and support permissions whenever a broader scope is used.

Related roles (2)

Common questions

When should I assign the CDN Endpoint Contributor Azure role?

Assign CDN Endpoint Contributor when you need to: Create or update a CDN endpoint under an approved profile, including the documented origin and delivery configuration.; and Operate the lifecycle of a defined CDN endpoint without granting management of every profile resource or Azure RBAC delegation.. Practical scope: A CDN endpoint is created under a named CDN profile. Assign the role at the endpoint, containing profile, or dedicated resource group needed for the task. At resource-group or broader scope, its deployment, alert, and support Actions apply to corresponding resources throughout that scope, not only to one endpoint.

What permissions does the CDN Endpoint Contributor Azure role grant?

The role definition grants 8 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Cdn/edgenodes/read; Microsoft.Cdn/operationresults/*; Microsoft.Cdn/profiles/endpoints/*; Microsoft.Insights/alertRules/*; and Microsoft.Resources/deployments/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the CDN Endpoint Contributor Azure role?

Key considerations when assigning CDN Endpoint Contributor: Changing an endpoint origin or delivery configuration can redirect traffic, change content delivery behavior, or make the endpoint unavailable.; Deleting an endpoint or misconfiguring its origin can cause a production outage even though the role cannot change RBAC assignments.; and The role has no DataActions, but its control-plane authority directly affects delivery of application content.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →