Azure Networking built-in role
CDN Profile Reader
Reads Azure CDN profiles and their endpoints without Microsoft.Cdn profile write permissions. The definition also grants classic alert-rule and support-ticket wildcards and lists additional Microsoft.Cdn Actions whose official operation descriptions are blank. It has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 8f96442b-4075-438f-813d-ad51ab4019af
Control-plane actions (11)
Microsoft.Authorization/*/readMicrosoft.Cdn/edgenodes/readMicrosoft.Cdn/operationresults/*Microsoft.Cdn/profiles/*/readMicrosoft.Insights/alertRules/*Microsoft.Resources/deployments/readMicrosoft.Cdn/profiles/afdendpoints/validateCustomDomain/actionMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*Microsoft.Cdn/profiles/CheckResourceUsage/actionMicrosoft.Cdn/profiles/endpoints/CheckResourceUsage/action
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The built-in definition is available throughout the Azure hierarchy. Assign it at the profile or dedicated resource group when possible; an assignment at a parent scope is inherited by all child profiles and endpoints. It contains only control-plane Actions and no DataActions, so it does not itself read origin data or delivered application content.
Common use cases (2)
- Show or list CDN profiles and inspect the endpoints contained by an approved profile without granting Microsoft.Cdn profile writes.
- Review CDN profile and endpoint configuration across a dedicated delivery resource group.
Prerequisites (2)
- Identify the profiles the principal must inspect and whether a profile or dedicated resource-group scope contains the complete review surface.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at the target scope.
Best practices (3)
- Keep the assignment at the profile or dedicated resource-group scope instead of exposing unrelated delivery profiles.
- Review the classic alert-rule and support-ticket wildcards separately from the Microsoft.Cdn read permissions.
- Do not assign operational meaning to additional Actions whose official descriptions are blank.
Security considerations (3)
- Profile reads expose endpoint, origin, custom-domain, route, and delivery configuration that can be useful to an attacker.
- The role can manage classic alert rules and support tickets at scopes where those Actions apply, despite its Reader name.
- It has no DataActions and does not itself grant access to application content or origin data.
Assignment guidance
Use CDN Profile Reader for profile-wide inspection without Microsoft.Cdn profile changes. Scope it to the profile or its dedicated resource group and explicitly account for the alert-rule and support Actions before approval.
Related roles (2)
- CDN Profile Contributor: Microsoft describes CDN Profile Contributor as the write-capable counterpart that manages profiles and their endpoints.
- CDN Endpoint Reader: CDN Endpoint Reader is narrower when the documented need is limited to one endpoint under the profile.
Editorial sources (6)
- Azure built-in roles for Networking →
Supports: Description, Practical scope, Common use cases, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- az cdn endpoint →
Supports: Practical scope, Common use cases, Prerequisites, Security considerations, Related roles. Retrieved 2026-07-16.
- az cdn profile →
Supports: Common use cases, Prerequisites, Security considerations. Retrieved 2026-07-16.