Azure Internet of Things built-in role
Firmware Analysis User
Firmware Analysis User uploads and analyzes firmware and views results without configuring workspaces. The published definition uses Azure control-plane Actions and no DataActions, while its provider-specific operations govern firmware workspaces, uploads, and results.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 53b2724d-1e51-44fa-b586-bcace0c82609
Control-plane actions (4)
Microsoft.IoTFirmwareDefense/*Microsoft.Authorization/*/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/deployments/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (5)
Microsoft.IoTFirmwareDefense/firmwareGroups/*Microsoft.IoTFirmwareDefense/register/actionMicrosoft.IoTFirmwareDefense/unregister/actionMicrosoft.IoTFirmwareDefense/workspaces/writeMicrosoft.IoTFirmwareDefense/workspaces/delete
Assignable scopes (1)
/
Practical scope
Assign at the resource group containing the firmware workspace. Subscription scope extends the same firmware access to all workspaces in the subscription and is unnecessary for a single-team workflow.
Common use cases (1)
- Let a firmware engineer submit an approved image for vulnerability analysis and review the resulting SBOM, CVE, hardening, and certificate findings.
Prerequisites (2)
- A firmware analysis workspace and allowed Azure Policy configuration are required; onboarding the service requires an Owner, Contributor, Security Admin, or Firmware Analysis Admin at subscription scope.
- Images submitted for analysis must be available to the operator, unencrypted, Linux-based, and smaller than 1 GB.
Best practices (2)
- Use Firmware Analysis User only for the documented user workflow and escalate to Firmware Analysis Admin only when workspace configuration is required.
- Assign at resource-group scope for an existing workspace and verify Azure Policy allows the Firmware Analysis Workspace resource type.
Security considerations (2)
- Uploaded firmware can contain proprietary code, signing material, credentials, or vulnerability evidence; the role can submit and view those sensitive images and results.
- The role does not grant access to unrelated resource groups or permission to invite other users, but a broader assignment exposes more firmware workspaces.
Assignment guidance
Assign Firmware Analysis User at the resource group containing the intended workspace to the firmware analyst who requires this access. Use a lower tier when the documented capability is unnecessary.
Related roles (2)
- Firmware Analysis Admin: Adds firmware workspace configuration and the complete upload, analysis, and result-viewing workflow.
- Firmware Analysis Reader: Restricts access to viewing and downloading existing analysis results.
Editorial sources (7)
- Azure built-in roles for Internet of Things - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Overview of Azure Role-Based Access Control for firmware analysis →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Tutorial: Analyze a firmware image with firmware analysis →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.