Azure Integration built-in role

Azure Resource Notifications System Topics Subscriber

Creates Azure Resource Notifications system topics and Event Grid event subscriptions for all currently exposed ARN topic types. The control-plane role is regularly updated to include future ARN topic types and grants no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 0b962ed2-6d56-471c-bd5f-3477d83a7ba4

Control-plane actions (10)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

ARN events are emitted exclusively at Azure subscription scope, so the effective notification boundary is the whole subscription even when the system topic resource is placed in a resource group. The subscribing principal should also have read access across that subscription.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (3)

Assignment guidance

Assign Azure Resource Notifications System Topics Subscriber only to the subscription-wide event platform identity that creates approved ARN topics and subscriptions. Require subscription read access, secure the destination, and use a custom role when automatic access to all future topic types is unacceptable.

Related roles (2)

Editorial sources (7)

Official Microsoft Learn documentation →