Azure Internet of Things built-in role

Azure Digital Twins Data Owner

Provides full Azure Digital Twins data-plane access to models, twins, relationships, commands, event routes, jobs, and graph queries. It contains DataActions only and does not manage the Azure Digital Twins instance through the Azure control plane.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: bcd981a7-7f74-457b-83e1-cceb9e632ffe

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (7)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Azure Digital Twins instance. For a principal that needs only selected models, twins, relationships, routes, jobs, or query operations, Microsoft documents creating a custom role rather than broadening this built-in owner.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Azure Digital Twins Data Owner on the individual instance only to the operator or workload identity that must mutate the full data plane. Use Data Reader or a custom role for query-only or data-area-specific access, and manage the Azure resource with a separate control-plane role.

Related roles (1)

Editorial sources (6)

Official Microsoft Learn documentation →