Azure Integration built-in role

Azure Service Bus Data Sender

Reads Service Bus queue, topic, and subscription metadata through control-plane Actions and sends messages through a data-plane DataAction. It does not grant receive access or the complete administration and data access of Data Owner.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 69a216fc-b8fb-44d8-bc22-1f3c2cd27a39

Control-plane actions (3)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the queue or topic that receives the producer's messages, at a namespace for all contained entities, or at resource-group or subscription scope for broader inherited access.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Azure Service Bus Data Sender to the producer identity on the individual queue or topic whenever possible. Broaden to namespace scope only when the same producer must send to multiple entities.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →