Azure Internet of Things built-in role

Firmware Analysis Reader

Firmware Analysis Reader views and downloads firmware analysis results without uploading images or configuring workspaces. The published definition uses Azure control-plane Actions and no DataActions, while its provider-specific operations govern firmware workspaces, uploads, and results.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 2a94a2fd-3c4f-45d1-847d-6585ba88af94

Control-plane actions (5)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (3)

Assignable scopes (1)

Practical scope

Assign at the resource group containing the firmware workspace. Subscription scope extends the same firmware access to all workspaces in the subscription and is unnecessary for a single-team workflow.

Common use cases (1)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Firmware Analysis Reader at the resource group containing the intended workspace to the firmware reviewer who requires this access. Use a lower tier when the documented capability is unnecessary.

Related roles (2)

Common questions

When should I assign the Firmware Analysis Reader Azure role?

Assign Firmware Analysis Reader when you need to: Let a security reviewer inspect and download existing firmware analysis results without submitting or deleting firmware.. Practical scope: Assign at the resource group containing the firmware workspace. Subscription scope extends the same firmware access to all workspaces in the subscription and is unnecessary for a single-team workflow.

What permissions does the Firmware Analysis Reader Azure role grant?

The role definition grants 5 combined control-plane and data-plane actions. Representative operations include: Microsoft.IoTFirmwareDefense/*/read; Microsoft.IoTFirmwareDefense/workspaces/firmwares/*; Microsoft.Authorization/*/read; Microsoft.Resources/subscriptions/resourceGroups/read; and Microsoft.Resources/deployments/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Firmware Analysis Reader Azure role?

Key considerations when assigning Firmware Analysis Reader: Read-only access still exposes firmware images and analysis results, including package inventories, vulnerabilities, certificates, and hardening findings.; and The role does not grant access to unrelated resource groups or permission to invite other users, but a broader assignment exposes more firmware workspaces.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →