Azure Internet of Things built-in role

Firmware Analysis Admin

Firmware Analysis Admin uploads and analyzes firmware, views results, and creates or deletes firmware workspaces. The published definition uses Azure control-plane Actions and no DataActions, while its provider-specific operations govern firmware workspaces, uploads, and results.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 9c1607d1-791d-4c68-885d-c7b7aaff7c8a

Control-plane actions (4)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Use subscription scope only when the principal must onboard firmware analysis; otherwise assign at the resource group containing the firmware workspace so access does not extend to unrelated workspaces.

Common use cases (1)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Firmware Analysis Admin at subscription scope to the administrator who must onboard firmware analysis. For ongoing administration of an existing workspace, assign it at the resource group containing that workspace; use Firmware Analysis User or Reader when workspace configuration is not required.

Related roles (2)

Common questions

When should I assign the Firmware Analysis Admin Azure role?

Assign Firmware Analysis Admin when you need to: Onboard a subscription to firmware analysis and administer the workspaces used by a device-security team.. Practical scope: Use subscription scope only when the principal must onboard firmware analysis; otherwise assign at the resource group containing the firmware workspace so access does not extend to unrelated workspaces.

What permissions does the Firmware Analysis Admin Azure role grant?

The role definition grants 4 combined control-plane and data-plane actions. Representative operations include: Microsoft.IoTFirmwareDefense/*; Microsoft.Authorization/*/read; Microsoft.Resources/subscriptions/resourceGroups/read; and Microsoft.Resources/deployments/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Firmware Analysis Admin Azure role?

Key considerations when assigning Firmware Analysis Admin: The role can create and delete workspaces as well as upload and view firmware, so compromise can alter both analysis inputs and the workspace lifecycle.; and The role does not grant access to unrelated resource groups or permission to invite other users, but a broader assignment exposes more firmware workspaces.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →