Azure Networking built-in role

CDN Profile Contributor

Manages Azure CDN and Azure Front Door Standard and Premium profiles and their endpoints through the Microsoft.Cdn profile control plane, but cannot create Azure RBAC role assignments. It also includes deployment, classic alert-rule, support, authorization-read, edge-node-read, and resource-group-read Actions and has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: ec156ff8-a8d1-4d15-830c-5b80698ca432

Control-plane actions (8)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The built-in definition is available throughout the Azure hierarchy. An assignment at a profile, resource group, subscription, or higher scope applies to that scope and inherited children. Because Microsoft.Cdn/profiles/* covers profile and child-resource management, keep the assignment near the intended profile boundary. The role grants no Azure RBAC data-plane access to origin or delivered content.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign CDN Profile Contributor only to the team or automation identity responsible for complete CDN or Front Door Standard/Premium profile management. Use a dedicated resource-group or profile scope, review the broad Microsoft.Cdn/profiles/* grant and ancillary Actions, and do not describe this profile-wide role as least privilege for endpoint-only work.

Related roles (3)

Common questions

When should I assign the CDN Profile Contributor Azure role?

Assign CDN Profile Contributor when you need to: Create and manage CDN or Front Door Standard/Premium profiles together with their endpoints and related profile child resources.; and Run deployment automation that owns the full Microsoft.Cdn profile lifecycle within a dedicated resource group.. Practical scope: The built-in definition is available throughout the Azure hierarchy. An assignment at a profile, resource group, subscription, or higher scope applies to that scope and inherited children. Because Microsoft.Cdn/profiles/* covers profile and child-resource management, keep the assignment near the intended profile boundary. The role grants no Azure RBAC data-plane access to origin or delivered content.

What permissions does the CDN Profile Contributor Azure role grant?

The role definition grants 8 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Cdn/edgenodes/read; Microsoft.Cdn/operationresults/*; Microsoft.Cdn/profiles/*; Microsoft.Insights/alertRules/*; and Microsoft.Resources/deployments/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the CDN Profile Contributor Azure role?

Key considerations when assigning CDN Profile Contributor: Profile-wide control can create, change, or delete profiles, endpoints, origins, routes, and other documented delivery configuration.; A configuration error can redirect traffic, expose an origin, weaken delivery controls, or remove a production endpoint.; and The role has no DataActions and cannot grant RBAC access, but its broad delivery-plane control remains security-sensitive.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (9)

Official Microsoft Learn documentation →