Azure Networking built-in role

CDN Endpoint Reader

Reads Azure CDN endpoint resources without endpoint write permissions. The definition also grants classic alert-rule and support-ticket wildcards, deployment reads, and an additional Microsoft.Cdn Action for which the official role page supplies no operation description. It has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 871e35f6-b5c1-49cc-a043-bde969a0f2cd

Control-plane actions (9)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The built-in definition is available throughout the Azure hierarchy. Assign it at the endpoint, containing profile or resource group, or another required scope; parent assignments are inherited by child resources. It has no DataActions and therefore does not itself read origin data or cached application content.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Use CDN Endpoint Reader when a principal must inspect endpoint configuration without changing Microsoft.Cdn endpoint resources. Keep the assignment at the endpoint or profile boundary and explicitly evaluate the alert-rule and support-ticket Actions during approval.

Related roles (2)

Common questions

When should I assign the CDN Endpoint Reader Azure role?

Assign CDN Endpoint Reader when you need to: Inspect CDN endpoint configuration, origins, and status without changing endpoint resources.; and Review endpoint configuration across one approved CDN profile while keeping Microsoft.Cdn endpoint resources read-only.. Practical scope: The built-in definition is available throughout the Azure hierarchy. Assign it at the endpoint, containing profile or resource group, or another required scope; parent assignments are inherited by child resources. It has no DataActions and therefore does not itself read origin data or cached application content.

What permissions does the CDN Endpoint Reader Azure role grant?

The role definition grants 9 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Cdn/edgenodes/read; Microsoft.Cdn/operationresults/*; Microsoft.Cdn/profiles/endpoints/*/read; Microsoft.Cdn/profiles/afdendpoints/validateCustomDomain/action; and Microsoft.Insights/alertRules/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the CDN Endpoint Reader Azure role?

Key considerations when assigning CDN Endpoint Reader: Endpoint reads can expose origin hostnames, delivery configuration, custom-domain state, and other topology information.; The role can manage classic alert rules and support tickets at scopes where those Actions apply, despite its Reader name.; and It has no DataActions and does not itself grant application-content or origin-data access.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →