Azure Integration built-in role

Azure Relay Sender

Provides entity-read control-plane access and the data-plane send operation for Azure Relay Hybrid Connections and WCF Relays. It does not grant listen access or full Relay administration.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 26baccc8-eea7-41f1-98f4-1762cc7f685d

Control-plane actions (2)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at one hybrid connection or WCF relay for entity-specific sending, at a Relay namespace for all contained entities, or at resource-group or subscription scope for broader inherited access.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Azure Relay Sender to the client workload identity on the specific Relay entity. Use Listener for receiving workloads and Owner only for principals that administer the Relay resources and require both data directions.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →