Azure Databases built-in role

Azure Managed Redis Contributor

Creates and manages Azure Managed Redis resources through the Azure control plane. It has broad Microsoft.Cache/redisEnterprise management Actions but no DataActions, so it does not authorize Redis commands or access to keys and values stored in the cache.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 3015e5ed-6856-4ab3-b2f0-b8492aa30ca6

Control-plane actions (9)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on an individual Azure Managed Redis resource or its dedicated resource group when the operator owns the complete cache lifecycle. A parent assignment is inherited by every cache below it. Cache data access is configured separately through Microsoft Entra users or service principals and Redis access permissions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Azure Managed Redis Contributor to the cache platform identity at the individual cache or dedicated resource-group scope. Grant Redis data access separately to application identities, and use Azure Managed Redis Reader when infrastructure changes are not required.

Related roles (1)

Editorial sources (7)

Official Microsoft Learn documentation →