Azure Storage built-in role
Data Lake Analytics Developer
Is the legacy job-function role for Azure Data Lake Analytics developers. It can submit jobs, monitor jobs and view U-SQL scripts submitted by any user, and cancel only the assignee's own jobs, while excluding account creation, deletion, ownership takeover, linked-store changes, firewall changes, and compute-policy changes. Azure Data Lake Analytics retired on February 29, 2024.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 47b7735b-770e-4598-a7da-8b91488b4c88
Control-plane actions (8)
Microsoft.Authorization/*/readMicrosoft.BigAnalytics/accounts/*Microsoft.DataLakeAnalytics/accounts/*Microsoft.Insights/alertRules/*Microsoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (14)
Microsoft.BigAnalytics/accounts/DeleteMicrosoft.BigAnalytics/accounts/TakeOwnership/actionMicrosoft.BigAnalytics/accounts/WriteMicrosoft.DataLakeAnalytics/accounts/DeleteMicrosoft.DataLakeAnalytics/accounts/TakeOwnership/actionMicrosoft.DataLakeAnalytics/accounts/WriteMicrosoft.DataLakeAnalytics/accounts/dataLakeStoreAccounts/WriteMicrosoft.DataLakeAnalytics/accounts/dataLakeStoreAccounts/DeleteMicrosoft.DataLakeAnalytics/accounts/storageAccounts/WriteMicrosoft.DataLakeAnalytics/accounts/storageAccounts/DeleteMicrosoft.DataLakeAnalytics/accounts/firewallRules/WriteMicrosoft.DataLakeAnalytics/accounts/firewallRules/DeleteMicrosoft.DataLakeAnalytics/accounts/computePolicies/WriteMicrosoft.DataLakeAnalytics/accounts/computePolicies/Delete
Assignable scopes (1)
/
Practical scope
The role is assignable throughout the Azure hierarchy, but its legacy Microsoft.DataLakeAnalytics and Microsoft.BigAnalytics permissions should be scoped to an existing Data Lake Analytics account. It has no DataActions; separate permissions on the Data Lake Store or Azure Storage data source are required to read or write job data.
Common use cases (2)
- Maintain or investigate a retained legacy Data Lake Analytics account during migration or shutdown.
- Submit and monitor U-SQL jobs and cancel the assignee's own jobs without administering the account or other users' jobs.
Prerequisites (3)
- Use only for an existing legacy account; Microsoft states that Azure Data Lake Analytics retired on February 29, 2024.
- Grant separate data-source ACLs or storage permissions required by the U-SQL job.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at the account scope.
Best practices (3)
- Do not use this role for new analytics deployments; follow Microsoft's migration direction to Azure Synapse Analytics or Microsoft Fabric.
- Keep the assignment on the legacy account and remove it when migration or decommissioning is complete.
- Review exposure of other users' U-SQL scripts because the role can monitor jobs submitted by any user.
Security considerations (3)
- The assignee can view U-SQL scripts and job status for other users, which can expose query logic and referenced data locations.
- Separate data-source permissions determine what job data can be accessed; this role alone does not grant that access.
- The role cannot take ownership of or cancel other users' jobs and cannot change account, firewall, linked-storage, or compute-policy configuration.
Assignment guidance
Assign Data Lake Analytics Developer only on an existing account for a bounded migration or maintenance task. Grant required data-source access separately, monitor access to other users' scripts, and remove the role as the retired service is decommissioned.
Related roles (1)
- Reader: The archived Data Lake Analytics guidance explicitly identifies Reader for job monitoring while Developer adds job submission and own-job cancellation.
Editorial sources (5)
- Azure built-in roles for Storage →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Manage Azure Data Lake Analytics using the Azure portal →
Supports: Description, Practical scope, Common use cases, Prerequisites, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Overview of Azure Data Lake Analytics →
Supports: Description, Prerequisites, Best practices, Assignment guidance. Retrieved 2026-07-16.