Azure Integration built-in role
Logic Apps Standard Contributor (Preview)
A preview control-plane role that manages all aspects of a Standard logic app and its workflows but cannot change Azure access or ownership. Its `Microsoft.Web/sites/*` and connection wildcards include sensitive configuration, callback-URL, API-connection-key, per-function-key, host-key, system-key, Functions-token, and master-key operations; it has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: ad710c24-b039-4e85-a019-deb4a06e8570
Control-plane actions (13)
Microsoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Resources/deployments/operations/readMicrosoft.Resources/subscriptions/operationresults/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*Microsoft.Web/*/readMicrosoft.Web/certificates/*Microsoft.Web/connectionGateways/*Microsoft.Web/connections/*Microsoft.Web/customApis/*Microsoft.Web/serverFarms/*Microsoft.Web/sites/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual Standard logic app resource whenever one app is administered. A resource-group assignment is inherited by every Standard logic app and supporting Microsoft.Web resource in that group.
Common use cases (2)
- Administer the lifecycle, workflows, connections, settings, certificates, hosting configuration, and operational state of one Standard logic app.
- Update migrated Standard workflow connections and resource configuration when the broad preview contributor boundary is approved.
Prerequisites (3)
- A Standard logic app must exist and the principal must need application-wide management rather than only workflow development or operations.
- Accept the Azure preview terms and validate the role against the current Standard hosting and deployment model.
- Confirm that the assignee is approved to retrieve security-sensitive app configuration, workflow callback URLs, API-connection keys, function keys, host and system keys, Functions tokens, and the master key within the assignment scope.
Best practices (3)
- Use Standard Developer, Operator, or Reader when application-wide management is unnecessary.
- Assign on the individual Standard logic app, protect and rotate exposed connection and Functions credentials, and secure sensitive app settings and run-history inputs and outputs.
- Keep Azure role-assignment authority on a separate access-administration role.
Security considerations (5)
- The role can reconfigure or delete Standard logic app resources, workflows, connections, certificates, hosting settings, and operational state.
- `Microsoft.Web/sites/*` includes the security-sensitive `config/list` operation, per-function key and Functions-token reads, host key listing, host-runtime function-key and master-key reads, and workflow-trigger callback-URL retrieval. The separate host-key response contains host-level function keys, system keys, and the master key.
- `Microsoft.Web/connections/*` includes API-connection key listing, and run history and connection configuration can contain sensitive business data and credentials even though the role has no DataActions.
- The role is preview and can change before general availability; it cannot change Azure access or ownership.
- The published supporting Actions include `Microsoft.Insights/alertRules/*` and `Microsoft.Support/*`; parent scope extends those wildcards beyond the Standard logic app.
Assignment guidance
Assign Logic Apps Standard Contributor (Preview) to the small platform group that owns one Standard logic app only after accepting its app-configuration, callback-URL, connection-key, per-function-key, host/system-key, Functions-token, and master-key authority. Use the narrower preview roles when their documented boundaries suffice, and review the assignment whenever the preview definition changes.
Related roles (3)
- Logic Apps Standard Developer (Preview): Limits changes to workflows, connections, and workflow-scoped settings.
- Logic Apps Standard Operator (Preview): Performs operational support without editing workflows or settings.
- Logic Apps Standard Reader (Preview): Provides read-only Standard logic app, workflow, and run-history access.
Editorial sources (10)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Secure access and data for workflows in Azure Logic Apps →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Permissions for Web and Mobile - Microsoft.Web →
Supports: Description, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Work with access keys in Azure Functions →
Supports: Description, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Web Apps - List Function Keys →
Supports: Description, Prerequisites, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Web Apps - List Host Keys →
Supports: Description, Prerequisites, Security considerations, Assignment guidance. Retrieved 2026-07-17.