Azure Integration built-in role

Azure Relay Owner

Provides full Azure Relay access across control-plane Actions and data-plane DataActions. Its `Microsoft.Relay/*` wildcard includes authorization-rule connection-string retrieval and primary or secondary key regeneration at namespace, Hybrid Connection, WCF Relay, and disaster-recovery scopes.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 2787bf04-f1f5-4bfe-8383-c8a24483ee38

Control-plane actions (1)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at one Relay entity or namespace according to the required administrative boundary. Resource-group and subscription assignments are inherited by all Relay resources below them and grant complete access across that wider scope.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Reserve Azure Relay Owner for the platform administrator on one Relay namespace or entity who is also approved to retrieve and rotate its authorization-rule credentials. Assign Listener and Sender separately to workload identities and avoid parent scope when unrelated Relay resources are present.

Related roles (2)

Editorial sources (7)

Official Microsoft Learn documentation →