Azure Integration built-in role

Logic Apps Standard Reader (Preview)

A preview control-plane role with read access to a Standard logic app, workflows, runs, and history. Its `Microsoft.Web/*/read` wildcard also exposes app configuration, function keys, Functions tokens, and master-key reads. It has no DataActions and cannot edit the Logic Apps assets, but its supporting Actions include classic alert-rule and support-ticket management.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 4accf36b-2c05-432f-91c8-5c532dff4c73

Microsoft Learn identifies this role as Preview in its published role name.

Control-plane actions (7)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Standard logic app whose resources and run history the principal may inspect. A resource-group assignment is inherited by every Standard app and related Microsoft.Web resource below it.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (5)

Assignment guidance

Assign Logic Apps Standard Reader (Preview) to approved reviewers on the individual Standard logic app only after accepting its configuration, function-key, Functions-token, and master-key reads. Secure run-history data and Functions credentials first, and review a different role only for a separately documented duty.

Related roles (3)

Editorial sources (9)

Official Microsoft Learn documentation →