Azure Web and Mobile built-in role

SignalR Service Owner

Provides full access to all Azure SignalR Service data-plane APIs, including REST operations, starting server connections, closing client connections, and temporary key or token generation. It does not directly create client connections; clients connect with generated tokens. The role has no control-plane Actions and does not manage the SignalR resource or Azure role assignments.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 7e4f1700-ea5a-4f59-8f37-079cfe29dce3

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the Azure SignalR Service resource used by the negotiation server. A parent assignment is inherited by every SignalR resource below it and gives the principal full data-plane access to each inherited instance.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign SignalR Service Owner directly on one Serverless-mode SignalR resource to the negotiation-server identity only after narrower roles are shown to be insufficient. Keep resource management and Azure RBAC delegation on separate control-plane roles.

Related roles (3)

Editorial sources (7)

Official Microsoft Learn documentation →