Azure Integration built-in role

Azure Relay Owner

Provides full Azure Relay access across control-plane Actions and data-plane DataActions. Its `Microsoft.Relay/*` wildcard includes authorization-rule connection-string retrieval and primary or secondary key regeneration at namespace, Hybrid Connection, WCF Relay, and disaster-recovery scopes.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 2787bf04-f1f5-4bfe-8383-c8a24483ee38

Control-plane actions (1)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at one Relay entity or namespace according to the required administrative boundary. Resource-group and subscription assignments are inherited by all Relay resources below them and grant complete access across that wider scope.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Reserve Azure Relay Owner for the platform administrator on one Relay namespace or entity who is also approved to retrieve and rotate its authorization-rule credentials. Assign Listener and Sender separately to workload identities and avoid parent scope when unrelated Relay resources are present.

Related roles (2)

Common questions

When should I assign the Azure Relay Owner Azure role?

Assign Azure Relay Owner when you need to: Administer a Relay namespace and its Hybrid Connections or WCF Relays while also testing send and listen behavior.; and Authorize a tightly controlled integration platform identity that genuinely needs complete Relay management and data operations.. Practical scope: Assign at one Relay entity or namespace according to the required administrative boundary. Resource-group and subscription assignments are inherited by all Relay resources below them and grant complete access across that wider scope.

What permissions does the Azure Relay Owner Azure role grant?

The role definition grants 2 combined control-plane and data-plane actions. Representative operations include: Microsoft.Relay/*; and Microsoft.Relay/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure Relay Owner Azure role?

Key considerations when assigning Azure Relay Owner: The role can create, modify, and delete Relay resources and can send and receive data through every inherited entity.; The Relay wildcard can return namespace, Hybrid Connection, WCF Relay, and disaster-recovery authorization-rule keys or connection strings and regenerate applicable primary or secondary keys.; and Compromise combines infrastructure control with both sides of Relay communication.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →