Azure Integration built-in role
Integration Service Environment Contributor
A retained control-plane role for managing Integration Service Environment resources without service data-plane access. Integration Service Environment retired on August 31, 2024, so the role should support only legacy inventory, migration verification, and assignment cleanup.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: a41e2c5b-bd99-4a07-88f4-9bf657a760b8
Control-plane actions (3)
Microsoft.Authorization/*/readMicrosoft.Support/*Microsoft.Logic/integrationServiceEnvironments/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Do not create a new assignment. For an existing ISE assignment, locate its originating ISE, resource-group, or parent scope and remove it there after migration; inherited assignments cannot be removed only from a child resource.
Common use cases (2)
- Inventory legacy ISE resources and Contributor assignments during post-retirement migration verification.
- Remove remaining ISE management authorization after workflows and dependencies have moved to a supported Logic Apps hosting model.
Prerequisites (2)
- A migration owner must identify any remaining ISE resources, workflows, integration accounts, connections, and role assignments.
- Validate the supported replacement workflow and its new Logic Apps roles before removing the legacy assignment.
Best practices (3)
- Do not grant this role for new work because ISE is retired.
- Use the documented Consumption or preview Standard Logic Apps roles on the supported replacement resource instead of carrying the ISE role forward.
- Remove legacy assignments and resources after migration validation and retention requirements are complete.
Security considerations (3)
- The role can manage legacy ISE resources throughout its inherited scope even though it has no DataActions.
- Retaining ISE management authority after retirement leaves unnecessary standing access on an unsupported service boundary.
- The published supporting Actions include `Microsoft.Support/*`; an inherited parent-scope assignment carries that wildcard across the effective scope until removed at its origin.
Assignment guidance
Do not assign Integration Service Environment Contributor. Locate and remove existing assignments after validating the migrated Logic Apps workload, and assign a current Logic Apps role separately on the replacement resource according to its actual duties.
Related roles (2)
- Logic Apps Standard Contributor (Preview): Provides broad management of a supported Standard logic app after migration; it is a preview role and not a direct permission-equivalent to the retired ISE role.
- Logic App Contributor: Provides management for supported Consumption logic apps rather than retired ISE infrastructure.
Editorial sources (7)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Azure Service Manager retirement →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Secure access and data for workflows in Azure Logic Apps →
Supports: Prerequisites, Best practices, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Remove Azure role assignments →
Supports: Practical scope, Common use cases, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.