Azure Integration built-in role

Logic Apps Standard Contributor (Preview)

A preview control-plane role that manages all aspects of a Standard logic app and its workflows but cannot change Azure access or ownership. Its `Microsoft.Web/sites/*` and connection wildcards include sensitive configuration, callback-URL, API-connection-key, per-function-key, host-key, system-key, Functions-token, and master-key operations; it has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: ad710c24-b039-4e85-a019-deb4a06e8570

Microsoft Learn identifies this role as Preview in its published role name.

Control-plane actions (13)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Standard logic app resource whenever one app is administered. A resource-group assignment is inherited by every Standard logic app and supporting Microsoft.Web resource in that group.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (5)

Assignment guidance

Assign Logic Apps Standard Contributor (Preview) to the small platform group that owns one Standard logic app only after accepting its app-configuration, callback-URL, connection-key, per-function-key, host/system-key, Functions-token, and master-key authority. Use the narrower preview roles when their documented boundaries suffice, and review the assignment whenever the preview definition changes.

Related roles (3)

Editorial sources (10)

Official Microsoft Learn documentation →