Azure Integration built-in role

Logic Apps Standard Contributor (Preview)

A preview control-plane role that manages all aspects of a Standard logic app and its workflows but cannot change Azure access or ownership. Its `Microsoft.Web/sites/*` and connection wildcards include sensitive configuration, callback-URL, API-connection-key, per-function-key, host-key, system-key, Functions-token, and master-key operations; it has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: ad710c24-b039-4e85-a019-deb4a06e8570

Microsoft Learn identifies this role as Preview in its published role name.

Control-plane actions (13)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Standard logic app resource whenever one app is administered. A resource-group assignment is inherited by every Standard logic app and supporting Microsoft.Web resource in that group.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (5)

Assignment guidance

Assign Logic Apps Standard Contributor (Preview) to the small platform group that owns one Standard logic app only after accepting its app-configuration, callback-URL, connection-key, per-function-key, host/system-key, Functions-token, and master-key authority. Use the narrower preview roles when their documented boundaries suffice, and review the assignment whenever the preview definition changes.

Related roles (3)

Common questions

When should I assign the Logic Apps Standard Contributor (Preview) Azure role?

Assign Logic Apps Standard Contributor (Preview) when you need to: Administer the lifecycle, workflows, connections, settings, certificates, hosting configuration, and operational state of one Standard logic app.; and Update migrated Standard workflow connections and resource configuration when the broad preview contributor boundary is approved.. Practical scope: Assign on the individual Standard logic app resource whenever one app is administered. A resource-group assignment is inherited by every Standard logic app and supporting Microsoft.Web resource in that group.

What permissions does the Logic Apps Standard Contributor (Preview) Azure role grant?

The role definition grants 13 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Insights/alertRules/*; Microsoft.Resources/deployments/operations/read; Microsoft.Resources/subscriptions/operationresults/read; Microsoft.Resources/subscriptions/resourceGroups/read; and Microsoft.Support/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Logic Apps Standard Contributor (Preview) Azure role?

Key considerations when assigning Logic Apps Standard Contributor (Preview): The role can reconfigure or delete Standard logic app resources, workflows, connections, certificates, hosting settings, and operational state.; `Microsoft.Web/sites/*` includes the security-sensitive `config/list` operation, per-function key and Functions-token reads, host key listing, host-runtime function-key and master-key reads, and workflow-trigger callback-URL retrieval. The separate host-key response contains host-level function keys, system keys, and the master key.; `Microsoft.Web/connections/*` includes API-connection key listing, and run history and connection configuration can contain sensitive business data and credentials even though the role has no DataActions.; and The role is preview and can change before general availability; it cannot change Azure access or ownership.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (10)

Official Microsoft Learn documentation →