Azure Integration built-in role
FHIR Data Contributor
Provides broad FHIR data-plane access across supported FHIR service resource paths. The published role uses wildcard DataActions but explicitly excludes the SMART-specific action; it has no control-plane Actions and does not manage the FHIR service resource.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 5a1fc7df-4bf1-4951-a576-89034ee01acd
Control-plane actions (0)
None — this role grants no control-plane management actions.
Data-plane actions (2)
Microsoft.HealthcareApis/services/fhir/resources/*Microsoft.HealthcareApis/workspaces/fhirservices/resources/*
Excluded actions (2)
Microsoft.HealthcareApis/services/fhir/resources/smart/actionMicrosoft.HealthcareApis/workspaces/fhirservices/resources/smart/action
Assignable scopes (1)
/
Practical scope
Assign on the individual FHIR service whose complete general data plane the principal administers. Parent-scope assignments inherit broad FHIR access to additional service instances.
Common use cases (2)
- Authorize a trusted FHIR data administrator or integration workload that genuinely needs all general FHIR data-plane operations.
- Execute documented bulk updates when the same trusted identity already owns broad FHIR data administration.
Prerequisites (2)
- The FHIR service must exist and the principal must authenticate with Microsoft Entra ID.
- Confirm that narrower Reader, Writer, Exporter, Importer, Converter, Bulk Operator, or SMART User roles do not satisfy the workflow.
Best practices (3)
- Reserve this broad role for a small FHIR data-administration group and assign it directly on one service.
- Use operation-specific roles for application identities and separate SMART clinical-scope access from general contributor access.
- Audit bulk, import, export, delete, reindex, and profile-definition operations performed by contributor identities.
Security considerations (3)
- The role can read and modify protected health information and perform broad administrative data operations across the FHIR repository.
- The published NotDataActions exclude the SMART-specific authorization action, so this role does not substitute for FHIR SMART User.
- A parent-scope assignment grants the same broad data-plane access to every inherited FHIR service.
Assignment guidance
Assign FHIR Data Contributor only to a trusted data administrator on the specific FHIR service after rejecting narrower role options. Assign FHIR SMART User separately for SMART-scoped application access and keep Azure resource lifecycle administration on a separate control-plane role.
Related roles (3)
- FHIR Data Writer: Provides a documented read, write, and soft-delete workflow without the Contributor wildcard boundary.
- FHIR Data Reader: Limits FHIR data access to reads and searches.
- FHIR SMART User: Provides SMART-specific authorization that Contributor explicitly excludes.
Editorial sources (8)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Configure Azure RBAC roles for Azure Health Data Services →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Supported FHIR Features →
Supports: Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Bulk update FHIR resources →
Supports: Common use cases, Best practices, Related roles. Retrieved 2026-07-17.