Azure Integration built-in role

EventGrid TopicSpaces Subscriber

Authorizes an MQTT v5 client using a Microsoft Entra JWT to subscribe to messages in Event Grid topic spaces. It combines Event Grid and Azure resource metadata reads, a write-capable classic alert-rule wildcard, and the topic-space subscribe DataAction; it does not grant publish access.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 4b0f2fd7-60b4-4eca-896f-4435034f8bf5

Control-plane actions (5)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on one Event Grid topic space for that subscription boundary, or on the namespace when the identity must subscribe across all topic spaces. Resource-group and subscription scopes inherit more broadly.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (4)

Assignment guidance

Assign EventGrid TopicSpaces Subscriber to the MQTT v5 consumer identity on the specific topic space. Use namespace scope only for an approved multi-topic-space subscriber and grant Publisher separately to identities that send messages.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →