Azure Web and Mobile built-in role

Azure Maps Data Reader

Reads immutable data through Azure Maps REST APIs. The role contains DataActions only and no control-plane Actions, so it authorizes Azure Maps data-plane requests but cannot modify map data, manage the Azure Maps account, or create Azure role assignments.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 423170ca-a8f6-4b0f-8487-9e4eb8f49bfa

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the Azure Maps account whose immutable REST APIs the principal must call. A parent-scope assignment is inherited by all Azure Maps accounts below it; Microsoft generally recommends account scope to prevent unintended access to other map accounts.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Azure Maps Data Reader to the workload identity or user group directly on one Azure Maps account after verifying that only immutable APIs are required. Use Search and Render Data Reader for the documented basic web-map scenario, a custom role for a smaller API set, and Data Contributor only when mutable operations are required.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →