Azure Integration built-in role
FHIR Data Writer
Reads, creates, updates, and soft deletes FHIR data through data-plane DataActions. The published definition also carries several documented FHIR operations, but it has no Azure control-plane Actions and does not manage the FHIR service resource.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 3f88fce4-5892-4214-ae73-ba5294559913
Control-plane actions (0)
None — this role grants no control-plane management actions.
Data-plane actions (18)
Microsoft.HealthcareApis/services/fhir/resources/readMicrosoft.HealthcareApis/services/fhir/resources/writeMicrosoft.HealthcareApis/services/fhir/resources/deleteMicrosoft.HealthcareApis/services/fhir/resources/export/actionMicrosoft.HealthcareApis/services/fhir/resources/resourceValidate/actionMicrosoft.HealthcareApis/services/fhir/resources/reindex/actionMicrosoft.HealthcareApis/services/fhir/resources/convertData/actionMicrosoft.HealthcareApis/services/fhir/resources/editProfileDefinitions/actionMicrosoft.HealthcareApis/services/fhir/resources/import/actionMicrosoft.HealthcareApis/workspaces/fhirservices/resources/readMicrosoft.HealthcareApis/workspaces/fhirservices/resources/writeMicrosoft.HealthcareApis/workspaces/fhirservices/resources/deleteMicrosoft.HealthcareApis/workspaces/fhirservices/resources/export/actionMicrosoft.HealthcareApis/workspaces/fhirservices/resources/resourceValidate/actionMicrosoft.HealthcareApis/workspaces/fhirservices/resources/reindex/actionMicrosoft.HealthcareApis/workspaces/fhirservices/resources/convertData/actionMicrosoft.HealthcareApis/workspaces/fhirservices/resources/editProfileDefinitions/actionMicrosoft.HealthcareApis/workspaces/fhirservices/resources/import/action
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual FHIR service whose clinical records the principal may change. Parent-scope assignments inherit write authority to additional FHIR services.
Common use cases (2)
- Authorize a clinical integration application to create and update FHIR resources and perform ordinary soft deletes.
- Support a data-curation workflow that requires validation and approved maintenance operations without general Azure resource administration.
Prerequisites (2)
- The FHIR service and client identity must exist, and the client must authenticate with Microsoft Entra ID.
- The application must enforce clinical validation, audit, retention, and recovery requirements for every write and soft delete.
Best practices (2)
- Assign directly on one FHIR service and restrict the role to identities whose documented workflow requires writes or soft deletes.
- Keep this assignment limited to workflows that require the documented read, write, and soft-delete capability; review separate current documentation for other FHIR operations.
Security considerations (3)
- The role can modify and soft delete protected health information, affecting clinical data integrity and downstream systems.
- Its published DataActions include more than basic create and update operations, so it should not be described as a minimal write-only role.
- It has no Azure resource-management Actions and does not grant Azure role-assignment authority.
Assignment guidance
Assign FHIR Data Writer to the approved clinical integration identity directly on the FHIR service only when it requires read, write, and soft-delete access. Review separate current documentation before granting a different FHIR operation boundary.
Editorial sources (7)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Configure Azure RBAC roles for Azure Health Data Services →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Supported FHIR Features →
Supports: Common use cases, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.