Azure Integration built-in role

FHIR Data Reader

Reads and searches FHIR data through data-plane DataActions across supported standalone and workspace FHIR service paths. It has no control-plane Actions and cannot write, delete, import, export, or convert data.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 4c8d0bbc-75d3-4935-991f-5f3c56d81508

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (2)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual FHIR service whose clinical data the principal may read. Parent-scope assignments inherit read access to additional FHIR services below them.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign FHIR Data Reader to the approved viewer or analytics identity directly on the FHIR service when the workflow requires only read and search access. Review separate current documentation before granting any operation beyond that boundary.

Common questions

When should I assign the FHIR Data Reader Azure role?

Assign FHIR Data Reader when you need to: Authorize a clinical viewer, reporting application, or research workflow to read and search FHIR resources without changing them.; and Give an auditor data-plane visibility into one FHIR repository while resource and data administration stay separate.. Practical scope: Assign on the individual FHIR service whose clinical data the principal may read. Parent-scope assignments inherit read access to additional FHIR services below them.

What permissions does the FHIR Data Reader Azure role grant?

The role definition grants 2 combined control-plane and data-plane actions. Representative operations include: Microsoft.HealthcareApis/services/fhir/resources/read; and Microsoft.HealthcareApis/workspaces/fhirservices/resources/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the FHIR Data Reader Azure role?

Key considerations when assigning FHIR Data Reader: Read and search access exposes protected health information, resource history, and clinical relationships available through FHIR queries.; and The role cannot modify FHIR data or manage the Azure resource, but a parent-scope assignment exposes every inherited FHIR service.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →