Azure Networking built-in role

CDN Profile Reader

Reads Azure CDN profiles and their endpoints without Microsoft.Cdn profile write permissions. The definition also grants classic alert-rule and support-ticket wildcards and lists additional Microsoft.Cdn Actions whose official operation descriptions are blank. It has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 8f96442b-4075-438f-813d-ad51ab4019af

Control-plane actions (11)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The built-in definition is available throughout the Azure hierarchy. Assign it at the profile or dedicated resource group when possible; an assignment at a parent scope is inherited by all child profiles and endpoints. It contains only control-plane Actions and no DataActions, so it does not itself read origin data or delivered application content.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Use CDN Profile Reader for profile-wide inspection without Microsoft.Cdn profile changes. Scope it to the profile or its dedicated resource group and explicitly account for the alert-rule and support Actions before approval.

Related roles (2)

Common questions

When should I assign the CDN Profile Reader Azure role?

Assign CDN Profile Reader when you need to: Show or list CDN profiles and inspect the endpoints contained by an approved profile without granting Microsoft.Cdn profile writes.; and Review CDN profile and endpoint configuration across a dedicated delivery resource group.. Practical scope: The built-in definition is available throughout the Azure hierarchy. Assign it at the profile or dedicated resource group when possible; an assignment at a parent scope is inherited by all child profiles and endpoints. It contains only control-plane Actions and no DataActions, so it does not itself read origin data or delivered application content.

What permissions does the CDN Profile Reader Azure role grant?

The role definition grants 11 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Cdn/edgenodes/read; Microsoft.Cdn/operationresults/*; Microsoft.Cdn/profiles/*/read; Microsoft.Insights/alertRules/*; and Microsoft.Resources/deployments/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the CDN Profile Reader Azure role?

Key considerations when assigning CDN Profile Reader: Profile reads expose endpoint, origin, custom-domain, route, and delivery configuration that can be useful to an attacker.; The role can manage classic alert rules and support tickets at scopes where those Actions apply, despite its Reader name.; and It has no DataActions and does not itself grant access to application content or origin data.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →