Azure Integration built-in role

FHIR Data Writer

Reads, creates, updates, and soft deletes FHIR data through data-plane DataActions. The published definition also carries several documented FHIR operations, but it has no Azure control-plane Actions and does not manage the FHIR service resource.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 3f88fce4-5892-4214-ae73-ba5294559913

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (18)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual FHIR service whose clinical records the principal may change. Parent-scope assignments inherit write authority to additional FHIR services.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (3)

Assignment guidance

Assign FHIR Data Writer to the approved clinical integration identity directly on the FHIR service only when it requires read, write, and soft-delete access. Review separate current documentation before granting a different FHIR operation boundary.

Editorial sources (7)

Official Microsoft Learn documentation →