Azure Identity built-in role

Domain Services Reader

Views Microsoft Entra Domain Services managed domains and related Azure network, deployment, monitoring, and diagnostic configuration without changing those resources.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 361898ef-9ed1-48c2-849c-a832951106bb

Control-plane actions (28)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The built-in definition is available throughout the Azure hierarchy. The assignment applies at the selected scope and inherited child scopes. Its permissions are read-oriented control-plane Actions across Domain Services and related resources; it has no DataActions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Domain Services Reader for view-only operations and troubleshooting at the smallest scope that includes the managed domain and the related network resources the principal must inspect. Escalate to Domain Services Contributor only for an approved change task.

Related roles (1)

Common questions

When should I assign the Domain Services Reader Azure role?

Assign Domain Services Reader when you need to: Inspect managed-domain status and configuration without making changes.; and Review related virtual-network, subnet, security-rule, route, deployment, metric, log, and diagnostic configuration for troubleshooting or audit work.. Practical scope: The built-in definition is available throughout the Azure hierarchy. The assignment applies at the selected scope and inherited child scopes. Its permissions are read-oriented control-plane Actions across Domain Services and related resources; it has no DataActions.

What permissions does the Domain Services Reader Azure role grant?

The role definition grants 28 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Resources/deployments/read; Microsoft.Resources/deployments/operations/read; Microsoft.Resources/deployments/operationstatuses/read; Microsoft.Resources/subscriptions/resourceGroups/read; and Microsoft.Insights/AlertRules/Read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Domain Services Reader Azure role?

Key considerations when assigning Domain Services Reader: Read-only access includes managed-domain, network, deployment, metric, log, and diagnostic metadata that can reveal environment topology.; The role cannot change the listed resources and has no DataActions, but broad inherited visibility can still be sensitive.; and This Azure role does not grant Microsoft Entra directory administration.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (4)

Official Microsoft Learn documentation →