Azure Integration built-in role

Azure Service Bus Data Receiver

Reads Service Bus entity metadata through control-plane Actions and receives messages through a data-plane DataAction. It does not grant send access or the complete administration and data access of Data Owner.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 4f6d3b9b-027b-4f4c-9142-0e5a2a2247e0

Control-plane actions (3)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the queue or topic subscription consumed by the identity, at a namespace for all contained entities, or at a broader inherited scope. Topic-subscription-level assignment requires tooling other than the Azure portal.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Azure Service Bus Data Receiver to the consumer identity on the individual queue or topic subscription. Use command-line or template tooling for topic-subscription scope, and broaden to the namespace only when the consumer must receive from multiple entities.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →