Azure Integration built-in role

Logic Apps Standard Operator (Preview)

A preview control-plane role for Standard logic app operations and support. It can enable and disable the app, resubmit workflow runs, create connections, and perform documented site and slot operations. Its read and host-runtime permissions also expose workflow callback URLs, function keys, Functions tokens, configuration, and a master-key operation even though two host-runtime operations are excluded.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: b70c96e9-66fe-4c09-b6e7-c98e69c98555

Microsoft Learn identifies this role as Preview in its published role name.

Control-plane actions (19)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (2)

Assignable scopes (1)

Practical scope

Assign on the individual Standard logic app operated by the support team. Resource-group scope inherits operational and connection authority across every Standard app and related site resource in that group.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (6)

Assignment guidance

Assign Logic Apps Standard Operator (Preview) to the operations group on the individual Standard logic app only after accepting its callback-URL, function-key, Functions-token, configuration-read, and remaining master-key authority. Use a separately reviewed role when run control is unnecessary or configuration changes are required.

Related roles (3)

Editorial sources (9)

Official Microsoft Learn documentation →