Azure Networking built-in role

Azure Front Door Profile Reader

Reads Azure Front Door Standard and Premium profiles and their endpoints without Microsoft.Cdn profile write permissions. The role definition also grants deployment and classic alert-rule wildcards and lists additional Microsoft.Cdn Actions whose operation descriptions are blank. It has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 662802e2-50f6-46b0-aed2-e834bacc6d12

Control-plane actions (17)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The definition is assignable throughout the Azure hierarchy. Assignments are effective at the selected scope and inherited by child resources. At resource-group, subscription, or management-group scope, the deployment and classic alert-rule Actions are not confined to a single Front Door profile.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Use Azure Front Door Profile Reader for principals that must inspect Standard or Premium profiles and endpoints without changing Microsoft.Cdn profile resources. Keep the scope to the profile or its dedicated resource group and explicitly review the ancillary deployment and alert permissions before approval.

Related roles (1)

Editorial sources (5)

Official Microsoft Learn documentation →