Azure Integration built-in role
EventGrid Contributor
Creates and manages Event Grid resources through broad control-plane Actions. It does not provide the dedicated event-publishing DataAction of EventGrid Data Sender, but its wildcard can return full event-subscription endpoint URLs and list or regenerate keys for topics, domains, partner namespaces, namespaces, and namespace topics.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 1e241071-0855-49ea-94dc-649edcd759de
Control-plane actions (6)
Microsoft.Authorization/*/readMicrosoft.EventGrid/*Microsoft.Insights/alertRules/*Microsoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the Event Grid topic, domain, namespace, or dedicated resource group the administrator owns. Parent assignments are inherited and broaden management authority to every Event Grid resource below them.
Common use cases (2)
- Administer Event Grid topics, domains, namespaces, system topics, and event subscriptions for an integration platform.
- Manage Event Grid infrastructure while publisher applications use a separate data-sender role.
Prerequisites (3)
- The assignee must own the Event Grid resource lifecycle and understand the destinations and sources connected through event subscriptions.
- Separate write access to non-webhook event-handler resources is required when creating subscriptions that target those handlers.
- The administrator must be approved to retrieve and regenerate keys for every Event Grid topic, domain, partner namespace, namespace, and namespace topic in scope.
Best practices (2)
- Use EventSubscription Contributor for principals that only manage subscriptions and Data Sender for applications that only publish events.
- Assign on the individual Event Grid resource or dedicated resource group and protect every returned key and full endpoint URL.
Security considerations (4)
- The role can create, change, and delete Event Grid resources and event routes throughout its scope.
- The Event Grid wildcard includes documented list-key and regenerate-key operations for custom topics, domains, partner namespaces, namespaces, and namespace topics, plus retrieval of a full event-subscription endpoint URL.
- Changing subscriptions can redirect events to a different destination or interrupt event delivery.
- The published supporting Actions include `Microsoft.Insights/alertRules/*` and `Microsoft.Support/*`; parent scope extends those wildcards beyond the Event Grid resource itself.
Assignment guidance
Reserve EventGrid Contributor for platform administrators approved to retrieve and rotate all Event Grid keys in scope, and assign it at the narrowest resource or dedicated resource-group scope. Use EventSubscription Contributor for routing-only administration and Data Sender for publishers.
Related roles (3)
- EventGrid EventSubscription Contributor: Limits control-plane changes to event-subscription operations rather than all Event Grid resources.
- EventGrid Data Sender: Provides event-publishing data access without broad Event Grid resource administration.
- EventGrid EventSubscription Reader: Reads event subscriptions without changing them.
Editorial sources (7)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations, Related roles. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Authorizing access to Event Grid resources →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Permissions for Integration - Microsoft.EventGrid →
Supports: Description, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.