Azure Web and Mobile built-in role

Azure Maps Data Contributor

Reads, writes, deletes, and performs other mutable Azure Maps data operations. The role contains DataActions only and no control-plane Actions, so it authorizes Azure Maps REST data-plane requests but does not manage the Azure Maps account resource or Azure role assignments.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 8f5e0ce6-4f7b-4dcf-bddf-e6f48634a204

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (4)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the Azure Maps account whose REST APIs the principal must use. An assignment on a resource group, subscription, or management group is inherited by every Azure Maps account below it; Microsoft generally recommends account scope to avoid unintended access to other map accounts.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Azure Maps Data Contributor to the application identity directly on one Azure Maps account only after verifying that mutable REST operations are required. Use Azure Maps Data Reader, Search and Render Data Reader, or a custom data role for read-only or API-specific workloads, and manage account configuration with a separate control-plane role.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →