Azure Networking built-in role

CDN Profile Contributor

Manages Azure CDN and Azure Front Door Standard and Premium profiles and their endpoints through the Microsoft.Cdn profile control plane, but cannot create Azure RBAC role assignments. It also includes deployment, classic alert-rule, support, authorization-read, edge-node-read, and resource-group-read Actions and has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: ec156ff8-a8d1-4d15-830c-5b80698ca432

Control-plane actions (8)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The built-in definition is available throughout the Azure hierarchy. An assignment at a profile, resource group, subscription, or higher scope applies to that scope and inherited children. Because Microsoft.Cdn/profiles/* covers profile and child-resource management, keep the assignment near the intended profile boundary. The role grants no Azure RBAC data-plane access to origin or delivered content.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign CDN Profile Contributor only to the team or automation identity responsible for complete CDN or Front Door Standard/Premium profile management. Use a dedicated resource-group or profile scope, review the broad Microsoft.Cdn/profiles/* grant and ancillary Actions, and do not describe this profile-wide role as least privilege for endpoint-only work.

Related roles (3)

Editorial sources (9)

Official Microsoft Learn documentation →