An Azure service that is used to send push notifications to all major platforms from the cloud or on-premises environments.
Azure Notification Hubs does not support Microsoft Entra ID / Azure AD authentication for data plane access.
Based on the documented security baseline for Notification Hubs:
- Managed identity is not supported for Notification Hubs data plane
The service explicitly shows Managed Identities: Supported = False for data plane actions. - Service principals are not supported for Notification Hubs data plane
The service also shows Service Principals: Supported = False for data plane actions. - Azure AD authentication is not supported for Notification Hubs data plane
The baseline states Azure AD Authentication Required for Data Plane Access: Supported = False. - Azure RBAC for Notification Hubs data plane is not supported
The baseline states Azure RBAC for Data Plane: Supported = False. That matches what was observed in IAM: no data actions, no usable data-plane RBAC role, and no custom role dataActions forMicrosoft.NotificationHubs. - Conditional Access and Key Vault integration are also not supported for Notification Hubs data plane
The baseline lists both as unsupported for this service. - The supported security model for Notification Hubs is SAS
Notification Hubs uses an entity-level security scheme called Shared Access Signature (SAS), which is automatically created when creating a hub.
Answers to the specific questions:
- Q1: No. Notification Hubs does not support AAD bearer token or managed identity authentication for data plane operations such as sending notifications or managing installations.
- Q2: There is no RBAC data-plane role or permission to assign for this scenario, because Azure RBAC for Notification Hubs data plane is not supported.
- Q3: The provided context confirms only that Azure RBAC for Notification Hubs data plane is unsupported. That explains why no data actions appear. It does not provide region or tenant availability details for the role GUID mentioned.
- Q4: The provided context does not document a bearer-token audience for Notification Hubs, and the service baseline indicates Azure AD data-plane auth is unsupported.
- Q5: The documented supported alternative is Shared Access Signature (SAS). Notification Hubs does not support managed identity or native Key Vault integration for its data plane, so the secure alternative within supported service capabilities is to use SAS-based access.