Azure Internet of Things built-in role

Azure Digital Twins Data Reader

Provides read-only Azure Digital Twins data-plane access to models, twins, relationships, event routes, job state, and graph queries. It has DataActions only and cannot configure the Azure Digital Twins instance or mutate graph data.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: d57506d4-4c8d-48b1-8587-93c323f6a5a3

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (8)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Azure Digital Twins instance. A broader Azure assignment is inherited by other instances, while a custom role can narrow access to selected Digital Twins data areas when the built-in reader is still too broad.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Azure Digital Twins Data Reader directly on the target instance to the application identity or user group that needs graph inspection. Move to Data Owner only for approved mutations, or to a custom role for a smaller data-area boundary.

Related roles (1)

Editorial sources (6)

Official Microsoft Learn documentation →