Azure Integration built-in role

EventGrid EventSubscription Contributor

Creates, updates, and deletes Event Grid event subscriptions without granting general topic creation or Event Grid resource administration. The role contains control-plane Actions only and can retrieve subscription information associated with event destinations.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 428e0ff0-5e57-4d9c-a221-2c70d0e0a443

Control-plane actions (9)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

For a system topic, assign on the Azure source resource that publishes the events. For a custom topic or domain topic, assign on that topic. Parent assignments inherit subscription-management authority across additional sources.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (4)

Assignment guidance

Assign EventGrid EventSubscription Contributor on the specific source resource, custom topic, or domain topic to the routing operator. Grant destination write access separately when required, and use Reader when no route change is needed.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →