Azure Internet of Things built-in role

Azure Device Registry Onboarding

Provisions and removes Azure Device Registry namespaces, linked IoT Hub and Device Provisioning Service resources, credential policies, and DPS enrollments for the documented X.509 certificate-management setup. It combines broad control-plane Actions with DPS enrollment DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 547f7f0a-69c0-4807-bd9e-0321dfb66a84

Control-plane actions (8)

Data-plane actions (2)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Use the resource group that contains the new IoT Hub, Device Registry namespace, and DPS instance for the onboarding workflow. Subscription scope is broader than the documented deployment and affects additional IoT resources.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Azure Device Registry Onboarding at the resource group containing the planned integration to the deployment identity for a time-bounded setup or deboarding operation. After validation, remove it and grant Azure Device Registry Contributor to the runtime managed identity on the namespace.

Related roles (1)

Editorial sources (6)

Official Microsoft Learn documentation →