Azure Internet of Things built-in role

Device Provisioning Service Data Reader

Device Provisioning Service Data Reader provides read-only access to Device Provisioning Service APIs through DataActions only. It does not manage the DPS Azure resource through the control plane and does not authenticate device registration APIs.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 10745317-c249-44a1-a5ce-3a4353c0bbd8

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Device Provisioning Service instance. Azure RBAC does not support enrollment-group or individual-enrollment assignment scope, and broader assignments are inherited by every DPS instance below them.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Device Provisioning Service Data Reader on the target DPS instance to the Microsoft Entra principal that calls the supported service APIs. Keep device attestation separate, avoid parent-scope assignments, and use the companion role or a custom role when the required operation set differs.

Related roles (1)

Editorial sources (6)

Official Microsoft Learn documentation →