Azure Networking built-in role
CDN Profile Contributor
Manages Azure CDN and Azure Front Door Standard and Premium profiles and their endpoints through the Microsoft.Cdn profile control plane, but cannot create Azure RBAC role assignments. It also includes deployment, classic alert-rule, support, authorization-read, edge-node-read, and resource-group-read Actions and has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: ec156ff8-a8d1-4d15-830c-5b80698ca432
Control-plane actions (8)
Microsoft.Authorization/*/readMicrosoft.Cdn/edgenodes/readMicrosoft.Cdn/operationresults/*Microsoft.Cdn/profiles/*Microsoft.Insights/alertRules/*Microsoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The built-in definition is available throughout the Azure hierarchy. An assignment at a profile, resource group, subscription, or higher scope applies to that scope and inherited children. Because Microsoft.Cdn/profiles/* covers profile and child-resource management, keep the assignment near the intended profile boundary. The role grants no Azure RBAC data-plane access to origin or delivered content.
Common use cases (2)
- Create and manage CDN or Front Door Standard/Premium profiles together with their endpoints and related profile child resources.
- Run deployment automation that owns the full Microsoft.Cdn profile lifecycle within a dedicated resource group.
Prerequisites (2)
- Define the approved profile tier, resource group, endpoints, origins, domains, routes, and security configuration before granting profile-wide management.
- Identify the automation identity, group, or administrator and the narrowest scope containing only the profiles it must manage; the assigning administrator needs role-assignment write permission there.
Best practices (3)
- Use this role only when profile-level management is required; otherwise select a role whose published Actions match the narrower task.
- Keep profiles in a dedicated resource group or assign directly at the profile when practical, and review inherited parent-scope access.
- Protect origins, enable appropriate WAF and logging controls for Front Door, and test routing, caching, domain, and TLS changes before production rollout.
Security considerations (3)
- Profile-wide control can create, change, or delete profiles, endpoints, origins, routes, and other documented delivery configuration.
- A configuration error can redirect traffic, expose an origin, weaken delivery controls, or remove a production endpoint.
- The role has no DataActions and cannot grant RBAC access, but its broad delivery-plane control remains security-sensitive.
Assignment guidance
Assign CDN Profile Contributor only to the team or automation identity responsible for complete CDN or Front Door Standard/Premium profile management. Use a dedicated resource-group or profile scope, review the broad Microsoft.Cdn/profiles/* grant and ancillary Actions, and do not describe this profile-wide role as least privilege for endpoint-only work.
Related roles (3)
- CDN Profile Reader: Microsoft describes CDN Profile Reader as the read-only counterpart for CDN profiles and their endpoints.
- CDN Endpoint Contributor: CDN Endpoint Contributor is narrower for CDN endpoint management because current CDN documentation places endpoints under profiles.
- Azure Front Door Profile Reader: Microsoft describes Azure Front Door Profile Reader as the read-only counterpart for Front Door Standard and Premium profiles and endpoints.
Editorial sources (9)
- Azure built-in roles for Networking →
Supports: Description, Practical scope, Common use cases, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- az cdn endpoint →
Supports: Practical scope, Common use cases, Prerequisites, Related roles. Retrieved 2026-07-16.
- az cdn profile →
Supports: Common use cases, Prerequisites. Retrieved 2026-07-16.
- Quickstart: Create an Azure Front Door using the Azure portal →
Supports: Common use cases, Prerequisites, Best practices. Retrieved 2026-07-16.
- What is Azure Front Door Manager? →
Supports: Practical scope, Common use cases, Security considerations, Related roles. Retrieved 2026-07-16.
- Add a new endpoint with Front Door manager →
Supports: Best practices, Security considerations. Retrieved 2026-07-16.