Azure Management and governance built-in role

Template Spec Reader

Reads Azure Resource Manager template specs and their versions. Microsoft documents that read access is sufficient to reference a template spec for deployment, but the principal still needs separate permissions to create the target deployment and every resource in it.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 392ae280-861d-42bd-9ea5-08ee6d83b80e

Control-plane actions (1)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign on one template spec or the dedicated library resource group. The read assignment controls access to stored template content, not authority at the deployment target scope.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign to template consumers at the individual spec or library resource group. Add only the separate target-scope deployment permissions required by the approved template.

Related roles (1)

Editorial sources (5)

Official Microsoft Learn documentation →