Azure Integration built-in role
Integration Service Environment Developer
A retained control-plane role that allowed developers to read and join an Integration Service Environment while creating or updating workflows, integration accounts, and API connections associated with it. ISE retired on August 31, 2024, so this is legacy migration and cleanup access only.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: c7aa55d3-1abb-444a-a5ca-5e51e485d6ec
Control-plane actions (4)
Microsoft.Authorization/*/readMicrosoft.Support/*Microsoft.Logic/integrationServiceEnvironments/readMicrosoft.Logic/integrationServiceEnvironments/*/join/action
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Do not create a new assignment. For an existing assignment, identify its originating scope and remove it after the migrated workflows, integration accounts, and connections are validated; parent assignments remain inherited until removed at the parent.
Common use cases (2)
- Identify developers and automation that still hold legacy ISE Developer assignments during post-retirement cleanup.
- Validate that migrated workflows, integration accounts, and connections no longer depend on the legacy assignment before removal.
Prerequisites (2)
- A migration owner must map the old ISE workflows, integration accounts, API connections, principals, and assignment scopes to supported replacements.
- Assign current Logic Apps access on the replacement resource independently before removing required legacy access.
Best practices (3)
- Do not grant ISE Developer for new work because the hosting environment is retired.
- Use the preview Logic Apps Standard Developer role for a supported Standard workflow-development boundary, while separately reviewing connections and application-wide settings.
- Remove the legacy role after migration validation and clean up inherited parent-scope assignments.
Security considerations (3)
- The legacy role can authorize workflow, integration-account, and API-connection changes associated with a retired ISE.
- Stale developer authorization can preserve access to connection and workflow configuration after the workload has moved.
- The published supporting Actions include `Microsoft.Support/*`; an inherited parent-scope assignment carries that wildcard across the effective scope until removed at its origin.
Assignment guidance
Do not assign Integration Service Environment Developer. Replace any required development access with a current Logic Apps role on the migrated resource, then remove the legacy assignment at its originating scope.
Related roles (2)
- Logic Apps Standard Developer (Preview): Provides a supported Standard workflow-development role after migration; it is preview and not a direct permission-equivalent.
- Logic App Contributor: Manages supported Consumption logic apps rather than retired ISE resources.
Editorial sources (7)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Azure Service Manager retirement →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Secure access and data for workflows in Azure Logic Apps →
Supports: Prerequisites, Best practices, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Remove Azure role assignments →
Supports: Practical scope, Common use cases, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.