Azure Internet of Things built-in role
Firmware Analysis Admin
Firmware Analysis Admin uploads and analyzes firmware, views results, and creates or deletes firmware workspaces. The published definition uses Azure control-plane Actions and no DataActions, while its provider-specific operations govern firmware workspaces, uploads, and results.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 9c1607d1-791d-4c68-885d-c7b7aaff7c8a
Control-plane actions (4)
Microsoft.IoTFirmwareDefense/*Microsoft.Authorization/*/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/deployments/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Use subscription scope only when the principal must onboard firmware analysis; otherwise assign at the resource group containing the firmware workspace so access does not extend to unrelated workspaces.
Common use cases (1)
- Onboard a subscription to firmware analysis and administer the workspaces used by a device-security team.
Prerequisites (2)
- A firmware analysis workspace and allowed Azure Policy configuration are required; onboarding the service requires an Owner, Contributor, Security Admin, or Firmware Analysis Admin at subscription scope.
- Images submitted for analysis must be available to the operator, unencrypted, Linux-based, and smaller than 1 GB.
Best practices (2)
- Use Firmware Analysis User for analysts who do not configure workspaces and Reader for reviewers who do not upload images.
- Assign at resource-group scope for an existing workspace and verify Azure Policy allows the Firmware Analysis Workspace resource type.
Security considerations (2)
- The role can create and delete workspaces as well as upload and view firmware, so compromise can alter both analysis inputs and the workspace lifecycle.
- The role does not grant access to unrelated resource groups or permission to invite other users, but a broader assignment exposes more firmware workspaces.
Assignment guidance
Assign Firmware Analysis Admin at subscription scope to the administrator who must onboard firmware analysis. For ongoing administration of an existing workspace, assign it at the resource group containing that workspace; use Firmware Analysis User or Reader when workspace configuration is not required.
Related roles (2)
- Firmware Analysis User: Uploads and analyzes firmware without workspace configuration.
- Firmware Analysis Reader: Restricts access to viewing and downloading existing analysis results.
Editorial sources (7)
- Azure built-in roles for Internet of Things - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Overview of Azure Role-Based Access Control for firmware analysis →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Tutorial: Analyze a firmware image with firmware analysis →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.