Azure Networking built-in role

CDN Profile Reader

Reads Azure CDN profiles and their endpoints without Microsoft.Cdn profile write permissions. The definition also grants classic alert-rule and support-ticket wildcards and lists additional Microsoft.Cdn Actions whose official operation descriptions are blank. It has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 8f96442b-4075-438f-813d-ad51ab4019af

Control-plane actions (11)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The built-in definition is available throughout the Azure hierarchy. Assign it at the profile or dedicated resource group when possible; an assignment at a parent scope is inherited by all child profiles and endpoints. It contains only control-plane Actions and no DataActions, so it does not itself read origin data or delivered application content.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Use CDN Profile Reader for profile-wide inspection without Microsoft.Cdn profile changes. Scope it to the profile or its dedicated resource group and explicitly account for the alert-rule and support Actions before approval.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →