Azure Internet of Things built-in role

IoT Hub Registry Contributor

IoT Hub Registry Contributor creates, reads, updates, and deletes IoT Hub device and module identities through IoT Hub service-API DataActions. It grants no Azure Resource Manager Actions, so it does not configure the IoT hub resource or create Azure role assignments.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 4ea46cd5-c1b2-4a8e-910b-273211f9ce47

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual IoT hub. IoT Hub does not support a smaller Azure assignment scope for a device identity, so resource-group, subscription, or management-group assignments broaden access to every inherited hub.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign IoT Hub Registry Contributor to the service client or operator on the one IoT hub only after matching the required API operations to this role. Use a narrower built-in or custom data role when the complete published capability is unnecessary, and add Azure Reader separately only for portal navigation.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →