Azure Analytics built-in role

Schema Registry Reader

Reads and lists Event Hubs Schema Registry groups and retrieves schemas. Reading schema-group resource descriptions is a control-plane Action, while retrieving schemas is a data-plane DataAction.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 2c56ea50-c6b3-40a6-83c0-9d98858bc7d2

Control-plane actions (1)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Microsoft documents assigning Schema Registry roles to an application security principal at the Event Hubs namespace. A role assigned at resource-group or subscription scope is inherited by every matching namespace below it and broadens schema visibility beyond one registry.

Common use cases (1)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Schema Registry Reader to the producer or consumer application security principal at the Event Hubs namespace containing the required schema groups. Use Schema Registry Contributor only for principals that manage schema groups or schema versions.

Related roles (1)

Editorial sources (6)

Official Microsoft Learn documentation →