Azure Integration built-in role
FHIR Data Reader
Reads and searches FHIR data through data-plane DataActions across supported standalone and workspace FHIR service paths. It has no control-plane Actions and cannot write, delete, import, export, or convert data.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 4c8d0bbc-75d3-4935-991f-5f3c56d81508
Control-plane actions (0)
None — this role grants no control-plane management actions.
Data-plane actions (2)
Microsoft.HealthcareApis/services/fhir/resources/readMicrosoft.HealthcareApis/workspaces/fhirservices/resources/read
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual FHIR service whose clinical data the principal may read. Parent-scope assignments inherit read access to additional FHIR services below them.
Common use cases (2)
- Authorize a clinical viewer, reporting application, or research workflow to read and search FHIR resources without changing them.
- Give an auditor data-plane visibility into one FHIR repository while resource and data administration stay separate.
Prerequisites (2)
- The FHIR service and client identity must exist, and the client must authenticate with Microsoft Entra ID.
- The reader must be approved to access the protected health information available in the assigned service.
Best practices (2)
- Assign directly on one FHIR service and use a dedicated application identity for each clinical or analytics trust boundary.
- Keep the assignment limited to workflows that require the documented read and search capability.
Security considerations (2)
- Read and search access exposes protected health information, resource history, and clinical relationships available through FHIR queries.
- The role cannot modify FHIR data or manage the Azure resource, but a parent-scope assignment exposes every inherited FHIR service.
Assignment guidance
Assign FHIR Data Reader to the approved viewer or analytics identity directly on the FHIR service when the workflow requires only read and search access. Review separate current documentation before granting any operation beyond that boundary.
Editorial sources (6)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Configure Azure RBAC roles for Azure Health Data Services →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.