Azure Monitor built-in role

Data Purger

Authorizes purge operations for Application Insights and Log Analytics data. Azure RBAC publishes purge as control-plane Actions and the role has no DataActions, but invoking those Actions deletes matching analytics records through a destructive, non-reversible data operation.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 150f5e0c-0603-4f03-8c7f-cf70034c4e90

Control-plane actions (4)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the specific Log Analytics workspace or Application Insights resource containing the personal data that must be purged. A resource-group or broader assignment is inherited by every matching analytics resource below that scope.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Grant Data Purger only at the Log Analytics workspace or Application Insights resource covered by an approved GDPR request. Verify the query predicate before submission and avoid a parent scope that includes unrelated analytics data.

Related roles (1)

Editorial sources (5)

Official Microsoft Learn documentation →