Azure Integration built-in role

FHIR Data Bulk Operator

Performs FHIR bulk operations through data-plane DataActions. The published role includes FHIR resource reads, writes, deletes, export, reindex, import, hard delete, and bulk-operator operations across supported FHIR service resource paths; it has no control-plane Actions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 804db8d3-32c7-4ad4-a975-3f6f90d5f5f5

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (16)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual FHIR service instance where bulk operations are approved. For Azure Health Data Services, the scope resource ID includes the workspace and FHIR service; parent assignments inherit the same data access to additional services.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign FHIR Data Bulk Operator to a dedicated maintenance identity on the specific FHIR service only for approved bulk operations. Require preflight search validation, recovery planning, audit review, and remove the assignment when the maintenance window ends.

Related roles (2)

Editorial sources (7)

Official Microsoft Learn documentation →