Azure Integration built-in role
Logic Apps Standard Developer (Preview)
A preview control-plane role for creating and editing workflows, connections, and workflow-scoped settings in a Standard logic app. Its explicit configuration-list and host-runtime operations expose security-sensitive settings, workflow callback URLs, function keys, Functions tokens, and the master key; it cannot make application-wide changes such as virtual network integration, and App Service plans are not supported by this role.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 523776ba-4eb2-4600-a3c8-f2dc93da4bdb
Control-plane actions (25)
Microsoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Resources/deployments/operations/readMicrosoft.Resources/subscriptions/operationresults/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*Microsoft.Web/*/readMicrosoft.Web/connections/*Microsoft.Web/customApis/*Microsoft.Web/sites/config/list/Actionmicrosoft.web/sites/config/Writemicrosoft.web/sites/config/web/appsettings/deletemicrosoft.web/sites/config/web/appsettings/writemicrosoft.web/sites/deployWorkflowArtifacts/actionmicrosoft.web/sites/hostruntime/*microsoft.web/sites/listworkflowsconnections/actionMicrosoft.Web/sites/publish/Actionmicrosoft.web/sites/slots/config/appsettings/writeMicrosoft.Web/sites/slots/config/list/Actionmicrosoft.web/sites/slots/config/web/appsettings/deletemicrosoft.web/sites/slots/deployWorkflowArtifacts/actionmicrosoft.web/sites/slots/listworkflowsconnections/actionMicrosoft.Web/sites/slots/publish/Actionmicrosoft.web/sites/workflows/*microsoft.web/sites/workflowsconfiguration/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual Standard logic app where the developer owns workflows. A resource-group assignment broadens workflow, connection, and settings authority to every inherited Standard app and related Microsoft.Web resource.
Common use cases (2)
- Let a workflow developer create and update Standard workflows, connections, and workflow configuration without full application administration.
- Deploy and maintain workflow artifacts for one Standard logic app while platform settings stay with a separate contributor.
Prerequisites (3)
- A Standard logic app must already exist and the workflow team must have an approved connection and settings model.
- Application-wide networking, hosting-plan, and access changes must be handled by separately authorized platform administrators.
- The workflow team must be approved to retrieve publishing credentials, app settings, connection strings, workflow callback URLs, API-connection keys, function keys, Functions tokens, and the master key within the app scope.
Best practices (3)
- Assign on one Standard logic app and use Contributor only when application-wide resource management is required.
- Protect and rotate exposed settings, connection keys, function keys, Functions tokens, and the master key, and use secure inputs and outputs for sensitive run-history data.
- Treat the role as preview and revalidate its supported operations before relying on it in production governance.
Security considerations (6)
- Workflow, connection, and app-setting changes can redirect data, change credentials, and alter automated business behavior.
- `sites/config/list` and its slot equivalent list security-sensitive publishing credentials, app settings, and connection strings; `Microsoft.Web/connections/*` also includes API-connection key listing.
- `sites/hostruntime/*` includes workflow-trigger callback-URL retrieval, host-runtime function-key reads, the master-key read, and broad Function App runtime actions. The separate `sites/host/listkeys/action` operation that returns host-level function keys, system keys, and the master key is not granted by this role.
- The role cannot make documented application-wide changes such as virtual network integration and does not support App Service plan administration.
- The role is preview and has no DataActions, but control-plane workflow and connection access remains security-sensitive.
- The published supporting Actions include `Microsoft.Insights/alertRules/*` and `Microsoft.Support/*`; parent scope extends those wildcards beyond the Standard logic app.
Assignment guidance
Assign Logic Apps Standard Developer (Preview) to the workflow-development group on the individual Standard logic app only after accepting its sensitive-configuration, callback-URL, connection-key, function-key, Functions-token, master-key, and host-runtime authority. Keep application-wide platform management and operational run control on separately reviewed assignments.
Related roles (3)
- Logic Apps Standard Contributor (Preview): Adds application-wide Standard logic app management.
- Logic Apps Standard Operator (Preview): Performs operational run and connection tasks without workflow or settings edits.
- Logic Apps Standard Reader (Preview): Provides read-only visibility into the app, workflows, runs, and history.
Editorial sources (9)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Secure access and data for workflows in Azure Logic Apps →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Permissions for Web and Mobile - Microsoft.Web →
Supports: Description, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Work with access keys in Azure Functions →
Supports: Description, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Web Apps - List Host Keys →
Supports: Security considerations. Retrieved 2026-07-17.