Azure Internet of Things built-in role
Azure IoT Operations Administrator
Creates, changes, and deletes Azure IoT Operations instances and downstream Azure IoT Operations and Azure Device Registry assets. The role uses Azure control-plane Actions and has no DataActions; dependency services such as Key Vault, Storage, and Arc have separate authorization.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 5bc02df6-6cd5-43fe-ad3d-4c93cf56cc16
Control-plane actions (13)
Microsoft.IoTOperations/*Microsoft.Authorization/*/readMicrosoft.DeviceRegistry/Assets/*Microsoft.DeviceRegistry/AssetEndpointProfiles/*Microsoft.DeviceRegistry/Namespaces/Assets/*Microsoft.DeviceRegistry/Namespaces/Devices/*Microsoft.DeviceRegistry/Namespaces/DiscoveredAssets/*Microsoft.DeviceRegistry/Namespaces/DiscoveredDevices/*Microsoft.DeviceRegistry/SchemaRegistries/*Microsoft.Insights/alertRules/*Microsoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Edge/sites/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the resource group containing the Azure IoT Operations instance and its downstream resources. A subscription assignment extends administration to every inherited instance and is broader than the documented deployment boundary.
Common use cases (2)
- Administer an existing Azure IoT Operations instance, assets, asset endpoint profiles, discovered assets and devices, schemas, and downstream resources.
- Give an operations team broad Azure-side management after onboarding is complete, without granting the onboarding role assignment capability.
Prerequisites (2)
- An Arc-enabled Kubernetes cluster and Azure IoT Operations deployment are required, and dependency roles for Key Vault, Storage, Arc, extensions, managed identities, monitoring, and secret synchronization must be reviewed separately.
- The built-in role does not automatically grant all dependency permissions; identify the exact end-to-end task before assigning additional roles.
Best practices (2)
- Use a documented custom viewer or task-specific custom role when full instance and downstream-resource administration is unnecessary.
- Assign on the deployment resource group, keep dependency assignments separate, and remove the Onboarding role after deployment.
Security considerations (2)
- The role can create, edit, and delete the IoT Operations instance and downstream Device Registry assets but does not include roleAssignments/write.
- Adding broad dependency roles can expand access to secrets, storage, Kubernetes extensions, and managed identities beyond this role definition.
Assignment guidance
Assign Azure IoT Operations Administrator on the deployment resource group to the operations team that must manage the instance and downstream assets. Grant dependency roles only for verified tasks and use Onboarding only for the initial Arc and deployment workflow.
Related roles (1)
- Azure IoT Operations Onboarding: Adds the deployment workflow and conditionally constrained role-assignment permission needed during onboarding.
Editorial sources (7)
- Azure built-in roles for Internet of Things - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Deployment overview - Azure IoT Operations →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Custom RBAC roles for your Azure IoT Operations resources →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.