Azure Analytics built-in role

Azure Event Hubs Data Receiver

Allows a principal to receive events from Azure Event Hubs. The role uses a control-plane Action to read consumer groups and a data-plane DataAction to receive events; it does not provide the complete access of Data Owner.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: a638d3c7-ab3a-418d-83e6-5f17a39d4fde

Control-plane actions (1)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at a consumer group when one consuming application needs access to its independent view of the event stream, at an event hub for its consumer groups, or at a namespace for all contained event hubs. Resource-group and subscription assignments are inherited more broadly; the Azure portal does not currently support consumer-group-level role assignment.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Azure Event Hubs Data Receiver to the consuming identity at the narrowest supported consumer-group, event-hub, or namespace scope. Use command-line tooling for consumer-group scope because the Azure portal does not currently support assignments at that level.

Related roles (2)

Editorial sources (7)

Official Microsoft Learn documentation →