Azure Integration built-in role

FHIR SMART User

Provides the FHIR data-plane actions required for SMART on FHIR authorization, including read, read-by-ID, search, and the SMART-specific action. Current Microsoft Learn feature guidance states that the role does not grant FHIR write access, despite older role-table wording that describes SMART access more broadly.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 4ba50f17-9666-485c-a643-ff00808643f0

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (8)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign approved end users on the individual FHIR service used by the SMART workflow. Azure RBAC establishes the service boundary for the user, while SMART clinical scopes and fhirUser or launch context further constrain each request.

Common use cases (2)

Prerequisites (2)

Best practices (4)

Security considerations (4)

Assignment guidance

Assign FHIR SMART User to each approved end user on the specific FHIR service, then configure the SMART client, narrow clinical scopes, and launch context separately. Do not recommend the role to the client application without current official evidence, and do not use FHIR Data Contributor as a substitute because its published definition excludes the SMART-specific action.

Related roles (2)

Editorial sources (8)

Official Microsoft Learn documentation →