Azure Internet of Things built-in role

Azure IoT Operations Onboarding

Connects the target cluster through Azure Arc and deploys Azure IoT Operations. It has broad IoT Operations control-plane access and roleAssignments/write, but its role-definition condition limits new assignments to Storage Blob Data Contributor and Azure Device Registry Administrator.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 7b7c71ed-33fa-4ed2-a91a-e56d5da260b5

Control-plane actions (10)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Conditions (1)

Assignable scopes (1)

Practical scope

Assign on the resource group used for the Azure IoT Operations deployment. The conditional delegation still follows Azure scope inheritance, so a subscription assignment exposes onboarding and the allowed role grants across every inherited deployment resource group.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Azure IoT Operations Onboarding on the target deployment resource group to the named deployment identity for the onboarding window. Verify its condition, complete and validate the deployment, then remove the role and grant the narrower administration or custom roles needed for operations.

Related roles (1)

Editorial sources (7)

Official Microsoft Learn documentation →