Azure Networking built-in role

CDN Endpoint Reader

Reads Azure CDN endpoint resources without endpoint write permissions. The definition also grants classic alert-rule and support-ticket wildcards, deployment reads, and an additional Microsoft.Cdn Action for which the official role page supplies no operation description. It has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 871e35f6-b5c1-49cc-a043-bde969a0f2cd

Control-plane actions (9)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The built-in definition is available throughout the Azure hierarchy. Assign it at the endpoint, containing profile or resource group, or another required scope; parent assignments are inherited by child resources. It has no DataActions and therefore does not itself read origin data or cached application content.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Use CDN Endpoint Reader when a principal must inspect endpoint configuration without changing Microsoft.Cdn endpoint resources. Keep the assignment at the endpoint or profile boundary and explicitly evaluate the alert-rule and support-ticket Actions during approval.

Related roles (2)

Editorial sources (5)

Official Microsoft Learn documentation →