Mods
Azure

IAM Role: Azure/Front Door/operator

PermissionGrant
microsoft.network/frontdoors/routingrules/writeoperator
microsoft.network/frontdoors/routingrules/deleteoperator
microsoft.network/frontdoors/backendpools/writeoperator
microsoft.network/frontdoors/backendpools/deleteoperator
microsoft.network/frontdoors/loadbalancingsettings/writeoperator
microsoft.network/frontdoors/loadbalancingsettings/deleteoperator
microsoft.resources/deployments/cancel/actionoperator
microsoft.resources/deployments/deleteoperator
microsoft.resources/deployments/validate/actionoperator
microsoft.resources/deployments/writeoperator
microsoft.network/frontdoors/readmetadata
microsoft.network/frontdoors/purge/actionmetadata
microsoft.network/frontdoors/validatecustomdomain/actionmetadata
microsoft.network/frontdoors/providers/microsoft.insights/metricdefinitions/readmetadata
microsoft.network/frontdoors/providers/microsoft.insights/logdefinitions/readmetadata
microsoft.network/frontdoors/providers/microsoft.insights/diagnosticsettings/readmetadata
microsoft.network/frontdoors/routingrules/readmetadata
microsoft.network/frontdoors/backendpools/readmetadata
microsoft.network/frontdoors/frontendendpoints/readmetadata
microsoft.network/frontdoors/frontendendpoints/enablehttps/actionmetadata
microsoft.network/frontdoors/frontendendpoints/disablehttps/actionmetadata
microsoft.network/frontdoors/loadbalancingsettings/readmetadata
microsoft.network/frontdoors/healthprobesettings/readmetadata
microsoft.network/frontdoorwebapplicationfirewallpolicies/readmetadata
microsoft.network/frontdoorwebapplicationfirewallmanagedrulesets/readmetadata
microsoft.network/checkfrontdoornameavailability/actionmetadata
microsoft.resources/deployments/operations/readmetadata
microsoft.resources/deployments/readmetadata
microsoft.resources/subscriptions/resourcegroups/readmetadata