Azure Integration built-in role

FHIR Data Contributor

Provides broad FHIR data-plane access across supported FHIR service resource paths. The published role uses wildcard DataActions but explicitly excludes the SMART-specific action; it has no control-plane Actions and does not manage the FHIR service resource.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 5a1fc7df-4bf1-4951-a576-89034ee01acd

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (2)

Excluded actions (2)

Assignable scopes (1)

Practical scope

Assign on the individual FHIR service whose complete general data plane the principal administers. Parent-scope assignments inherit broad FHIR access to additional service instances.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign FHIR Data Contributor only to a trusted data administrator on the specific FHIR service after rejecting narrower role options. Assign FHIR SMART User separately for SMART-scoped application access and keep Azure resource lifecycle administration on a separate control-plane role.

Related roles (3)

Common questions

When should I assign the FHIR Data Contributor Azure role?

Assign FHIR Data Contributor when you need to: Authorize a trusted FHIR data administrator or integration workload that genuinely needs all general FHIR data-plane operations.; and Execute documented bulk updates when the same trusted identity already owns broad FHIR data administration.. Practical scope: Assign on the individual FHIR service whose complete general data plane the principal administers. Parent-scope assignments inherit broad FHIR access to additional service instances.

What permissions does the FHIR Data Contributor Azure role grant?

The role definition grants 2 combined control-plane and data-plane actions. Representative operations include: Microsoft.HealthcareApis/services/fhir/resources/*; and Microsoft.HealthcareApis/workspaces/fhirservices/resources/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the FHIR Data Contributor Azure role?

Key considerations when assigning FHIR Data Contributor: The role can read and modify protected health information and perform broad administrative data operations across the FHIR repository.; The published NotDataActions exclude the SMART-specific authorization action, so this role does not substitute for FHIR SMART User.; and A parent-scope assignment grants the same broad data-plane access to every inherited FHIR service.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (8)

Official Microsoft Learn documentation →