Azure Integration built-in role

Integration Service Environment Contributor

A retained control-plane role for managing Integration Service Environment resources without service data-plane access. Integration Service Environment retired on August 31, 2024, so the role should support only legacy inventory, migration verification, and assignment cleanup.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: a41e2c5b-bd99-4a07-88f4-9bf657a760b8

Control-plane actions (3)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Do not create a new assignment. For an existing ISE assignment, locate its originating ISE, resource-group, or parent scope and remove it there after migration; inherited assignments cannot be removed only from a child resource.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Do not assign Integration Service Environment Contributor. Locate and remove existing assignments after validating the migrated Logic Apps workload, and assign a current Logic Apps role separately on the replacement resource according to its actual duties.

Related roles (2)

Common questions

When should I assign the Integration Service Environment Contributor Azure role?

Assign Integration Service Environment Contributor when you need to: Inventory legacy ISE resources and Contributor assignments during post-retirement migration verification.; and Remove remaining ISE management authorization after workflows and dependencies have moved to a supported Logic Apps hosting model.. Practical scope: Do not create a new assignment. For an existing ISE assignment, locate its originating ISE, resource-group, or parent scope and remove it there after migration; inherited assignments cannot be removed only from a child resource.

What permissions does the Integration Service Environment Contributor Azure role grant?

The role definition grants 3 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Support/*; and Microsoft.Logic/integrationServiceEnvironments/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Integration Service Environment Contributor Azure role?

Key considerations when assigning Integration Service Environment Contributor: The role can manage legacy ISE resources throughout its inherited scope even though it has no DataActions.; Retaining ISE management authority after retirement leaves unnecessary standing access on an unsupported service boundary.; and The published supporting Actions include `Microsoft.Support/*`; an inherited parent-scope assignment carries that wildcard across the effective scope until removed at its origin.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →