Azure Databases built-in role

Azure Managed Redis Reader

Reads Azure Managed Redis resources and configuration without changing them. It cannot retrieve access keys and has no DataActions, so it does not authorize Redis commands or access to cached keys and values.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: f287ba2f-f923-4464-a5bd-721c3951d32d

Control-plane actions (9)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Azure Managed Redis resource for one-cache visibility. Resource-group, subscription, or management-group assignments are inherited by all caches below the selected scope. Redis data access remains a separate Microsoft Entra and Redis permissions workflow.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Azure Managed Redis Reader directly on the cache for view-only support, audit, or monitoring. Add Contributor only for approved infrastructure changes and configure Redis data permissions separately when command or key access is required.

Related roles (1)

Editorial sources (5)

Official Microsoft Learn documentation →