Azure Internet of Things built-in role
Firmware Analysis Reader
Firmware Analysis Reader views and downloads firmware analysis results without uploading images or configuring workspaces. The published definition uses Azure control-plane Actions and no DataActions, while its provider-specific operations govern firmware workspaces, uploads, and results.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 2a94a2fd-3c4f-45d1-847d-6585ba88af94
Control-plane actions (5)
Microsoft.IoTFirmwareDefense/*/readMicrosoft.IoTFirmwareDefense/workspaces/firmwares/*Microsoft.Authorization/*/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/deployments/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (3)
Microsoft.IoTFirmwareDefense/firmwareGroups/*Microsoft.IoTFirmwareDefense/workspaces/firmwares/writeMicrosoft.IoTFirmwareDefense/workspaces/firmwares/delete
Assignable scopes (1)
/
Practical scope
Assign at the resource group containing the firmware workspace. Subscription scope extends the same firmware access to all workspaces in the subscription and is unnecessary for a single-team workflow.
Common use cases (1)
- Let a security reviewer inspect and download existing firmware analysis results without submitting or deleting firmware.
Prerequisites (2)
- A firmware analysis workspace and allowed Azure Policy configuration are required; onboarding the service requires an Owner, Contributor, Security Admin, or Firmware Analysis Admin at subscription scope.
- Images submitted for analysis must be available to the operator, unencrypted, Linux-based, and smaller than 1 GB.
Best practices (2)
- Use Firmware Analysis Reader only for the documented reader workflow and escalate to Firmware Analysis Admin only when workspace configuration is required.
- Assign at resource-group scope for an existing workspace and verify Azure Policy allows the Firmware Analysis Workspace resource type.
Security considerations (2)
- Read-only access still exposes firmware images and analysis results, including package inventories, vulnerabilities, certificates, and hardening findings.
- The role does not grant access to unrelated resource groups or permission to invite other users, but a broader assignment exposes more firmware workspaces.
Assignment guidance
Assign Firmware Analysis Reader at the resource group containing the intended workspace to the firmware reviewer who requires this access. Use a lower tier when the documented capability is unnecessary.
Related roles (2)
- Firmware Analysis Admin: Adds firmware workspace configuration and the complete upload, analysis, and result-viewing workflow.
- Firmware Analysis User: Uploads and analyzes firmware without workspace configuration.
Editorial sources (7)
- Azure built-in roles for Internet of Things - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Overview of Azure Role-Based Access Control for firmware analysis →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Tutorial: Analyze a firmware image with firmware analysis →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.