Azure Integration built-in role

Integration Service Environment Developer

A retained control-plane role that allowed developers to read and join an Integration Service Environment while creating or updating workflows, integration accounts, and API connections associated with it. ISE retired on August 31, 2024, so this is legacy migration and cleanup access only.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: c7aa55d3-1abb-444a-a5ca-5e51e485d6ec

Control-plane actions (4)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Do not create a new assignment. For an existing assignment, identify its originating scope and remove it after the migrated workflows, integration accounts, and connections are validated; parent assignments remain inherited until removed at the parent.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Do not assign Integration Service Environment Developer. Replace any required development access with a current Logic Apps role on the migrated resource, then remove the legacy assignment at its originating scope.

Related roles (2)

Common questions

When should I assign the Integration Service Environment Developer Azure role?

Assign Integration Service Environment Developer when you need to: Identify developers and automation that still hold legacy ISE Developer assignments during post-retirement cleanup.; and Validate that migrated workflows, integration accounts, and connections no longer depend on the legacy assignment before removal.. Practical scope: Do not create a new assignment. For an existing assignment, identify its originating scope and remove it after the migrated workflows, integration accounts, and connections are validated; parent assignments remain inherited until removed at the parent.

What permissions does the Integration Service Environment Developer Azure role grant?

The role definition grants 4 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Support/*; Microsoft.Logic/integrationServiceEnvironments/read; and Microsoft.Logic/integrationServiceEnvironments/*/join/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Integration Service Environment Developer Azure role?

Key considerations when assigning Integration Service Environment Developer: The legacy role can authorize workflow, integration-account, and API-connection changes associated with a retired ISE.; Stale developer authorization can preserve access to connection and workflow configuration after the workload has moved.; and The published supporting Actions include `Microsoft.Support/*`; an inherited parent-scope assignment carries that wildcard across the effective scope until removed at its origin.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →