Azure Networking built-in role
Azure Front Door Profile Reader
Reads Azure Front Door Standard and Premium profiles and their endpoints without Microsoft.Cdn profile write permissions. The role definition also grants deployment and classic alert-rule wildcards and lists additional Microsoft.Cdn Actions whose operation descriptions are blank. It has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 662802e2-50f6-46b0-aed2-e834bacc6d12
Control-plane actions (17)
Microsoft.Authorization/*/readMicrosoft.Cdn/edgenodes/readMicrosoft.Cdn/operationresults/*Microsoft.Cdn/profiles/*/readMicrosoft.Insights/alertRules/*Microsoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Cdn/operationresults/profileresults/afdendpointresults/CheckCustomDomainDNSMappingStatus/actionMicrosoft.Cdn/profiles/queryloganalyticsmetrics/actionMicrosoft.Cdn/profiles/queryloganalyticsrankings/actionMicrosoft.Cdn/profiles/querywafloganalyticsmetrics/actionMicrosoft.Cdn/profiles/querywafloganalyticsrankings/actionMicrosoft.Cdn/profiles/afdendpoints/CheckCustomDomainDNSMappingStatus/actionMicrosoft.Cdn/profiles/Usages/actionMicrosoft.Cdn/profiles/afdendpoints/Usages/actionMicrosoft.Cdn/profiles/origingroups/Usages/actionMicrosoft.Cdn/profiles/rulesets/Usages/action
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The definition is assignable throughout the Azure hierarchy. Assignments are effective at the selected scope and inherited by child resources. At resource-group, subscription, or management-group scope, the deployment and classic alert-rule Actions are not confined to a single Front Door profile.
Common use cases (2)
- Inspect the endpoints, routes, domains, origin groups, and security-policy associations configured in a Front Door Standard or Premium profile without granting Microsoft.Cdn profile writes.
- Review a Front Door profile and its child endpoints as a read-only Front Door operator or auditor.
Prerequisites (2)
- Identify the Front Door profile or resource group the principal must inspect and the narrowest scope that contains it.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at the target scope.
Best practices (3)
- Assign at the individual profile or tightly bounded resource-group scope rather than at subscription scope when only one delivery configuration must be inspected.
- Account for the role's deployment and classic-alert operations during access review instead of classifying the entire definition as passive read access.
- Do not infer workflow capabilities from the additional Microsoft.Cdn Actions whose operation descriptions are blank on the official role page.
Security considerations (3)
- Profile reads expose delivery topology, origins, routes, custom domains, WAF associations, and other configuration relevant to application security.
- The role includes wildcard deployment and classic-alert Actions even though it cannot write Microsoft.Cdn profile resources.
- It has no DataActions and does not itself grant access to origin application data or customer traffic.
Assignment guidance
Use Azure Front Door Profile Reader for principals that must inspect Standard or Premium profiles and endpoints without changing Microsoft.Cdn profile resources. Keep the scope to the profile or its dedicated resource group and explicitly review the ancillary deployment and alert permissions before approval.
Related roles (1)
- CDN Profile Contributor: Microsoft describes CDN Profile Contributor as the write-capable role for Azure Front Door Standard and Premium profiles and their endpoints.
Editorial sources (5)
- Azure built-in roles for Networking →
Supports: Description, Practical scope, Common use cases, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- What is Azure Front Door Manager? →
Supports: Common use cases, Prerequisites, Security considerations. Retrieved 2026-07-16.