Azure Networking built-in role
CDN Endpoint Reader
Reads Azure CDN endpoint resources without endpoint write permissions. The definition also grants classic alert-rule and support-ticket wildcards, deployment reads, and an additional Microsoft.Cdn Action for which the official role page supplies no operation description. It has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 871e35f6-b5c1-49cc-a043-bde969a0f2cd
Control-plane actions (9)
Microsoft.Authorization/*/readMicrosoft.Cdn/edgenodes/readMicrosoft.Cdn/operationresults/*Microsoft.Cdn/profiles/endpoints/*/readMicrosoft.Cdn/profiles/afdendpoints/validateCustomDomain/actionMicrosoft.Insights/alertRules/*Microsoft.Resources/deployments/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The built-in definition is available throughout the Azure hierarchy. Assign it at the endpoint, containing profile or resource group, or another required scope; parent assignments are inherited by child resources. It has no DataActions and therefore does not itself read origin data or cached application content.
Common use cases (2)
- Inspect CDN endpoint configuration, origins, and status without changing endpoint resources.
- Review endpoint configuration across one approved CDN profile while keeping Microsoft.Cdn endpoint resources read-only.
Prerequisites (2)
- Identify the endpoint or profile the principal must inspect and the narrowest scope that contains it.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at the target scope.
Best practices (3)
- Assign at the individual endpoint or dedicated profile scope rather than broadly across unrelated profiles.
- Review the classic alert-rule and support-ticket wildcards because the role name does not make those ancillary Actions read-only.
- Do not assign operational meaning to the additional Microsoft.Cdn Action whose official description is blank.
Security considerations (3)
- Endpoint reads can expose origin hostnames, delivery configuration, custom-domain state, and other topology information.
- The role can manage classic alert rules and support tickets at scopes where those Actions apply, despite its Reader name.
- It has no DataActions and does not itself grant application-content or origin-data access.
Assignment guidance
Use CDN Endpoint Reader when a principal must inspect endpoint configuration without changing Microsoft.Cdn endpoint resources. Keep the assignment at the endpoint or profile boundary and explicitly evaluate the alert-rule and support-ticket Actions during approval.
Related roles (2)
- CDN Endpoint Contributor: Microsoft describes CDN Endpoint Contributor as the write-capable counterpart that can manage endpoints.
- CDN Profile Reader: CDN Profile Reader is the broader read role because Microsoft says it views profiles and their endpoints; current CDN commands place an endpoint under a profile.
Editorial sources (5)
- Azure built-in roles for Networking →
Supports: Description, Practical scope, Common use cases, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- az cdn endpoint →
Supports: Practical scope, Common use cases, Prerequisites, Security considerations, Related roles. Retrieved 2026-07-16.