Azure Identity built-in role
Domain Services Reader
Views Microsoft Entra Domain Services managed domains and related Azure network, deployment, monitoring, and diagnostic configuration without changing those resources.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 361898ef-9ed1-48c2-849c-a832951106bb
Control-plane actions (28)
Microsoft.Authorization/*/readMicrosoft.Resources/deployments/readMicrosoft.Resources/deployments/operations/readMicrosoft.Resources/deployments/operationstatuses/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Insights/AlertRules/ReadMicrosoft.Insights/AlertRules/Incidents/ReadMicrosoft.Insights/Logs/ReadMicrosoft.Insights/Metrics/readMicrosoft.Insights/DiagnosticSettings/readMicrosoft.Insights/DiagnosticSettingsCategories/ReadMicrosoft.AAD/domainServices/*/readMicrosoft.Network/virtualNetworks/readMicrosoft.Network/virtualNetworks/subnets/readMicrosoft.Network/virtualNetworks/virtualNetworkPeerings/readMicrosoft.Network/virtualNetworks/providers/Microsoft.Insights/diagnosticSettings/readMicrosoft.Network/virtualNetworks/providers/Microsoft.Insights/metricDefinitions/readMicrosoft.Network/azureFirewalls/readMicrosoft.Network/ddosProtectionPlans/readMicrosoft.Network/loadBalancers/readMicrosoft.Network/loadBalancers/*/readMicrosoft.Network/natGateways/readMicrosoft.Network/networkInterfaces/readMicrosoft.Network/networkSecurityGroups/defaultSecurityRules/readMicrosoft.Network/networkSecurityGroups/readMicrosoft.Network/networkSecurityGroups/securityRules/readMicrosoft.Network/routeTables/readMicrosoft.Network/routeTables/routes/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The built-in definition is available throughout the Azure hierarchy. The assignment applies at the selected scope and inherited child scopes. Its permissions are read-oriented control-plane Actions across Domain Services and related resources; it has no DataActions.
Common use cases (2)
- Inspect managed-domain status and configuration without making changes.
- Review related virtual-network, subnet, security-rule, route, deployment, metric, log, and diagnostic configuration for troubleshooting or audit work.
Prerequisites (2)
- Identify the managed domain and related network scope the principal must inspect.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at that scope.
Best practices (3)
- Use this role instead of Domain Services Contributor for inspection, audit, and troubleshooting tasks that require no changes.
- Scope the assignment to the resource group or other boundary containing the managed domain and approved dependencies.
- Review broad assignments because read access inherited from a parent can expose configuration for multiple managed domains and networks.
Security considerations (3)
- Read-only access includes managed-domain, network, deployment, metric, log, and diagnostic metadata that can reveal environment topology.
- The role cannot change the listed resources and has no DataActions, but broad inherited visibility can still be sensitive.
- This Azure role does not grant Microsoft Entra directory administration.
Assignment guidance
Assign Domain Services Reader for view-only operations and troubleshooting at the smallest scope that includes the managed domain and the related network resources the principal must inspect. Escalate to Domain Services Contributor only for an approved change task.
Related roles (1)
- Domain Services Contributor: Adds managed-domain and related network changes when read-only access is insufficient.
Editorial sources (4)
- Azure built-in roles for Identity →
Supports: Description, Practical scope, Common use cases, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites. Retrieved 2026-07-16.
- Azure roles, Microsoft Entra roles, and classic subscription administrator roles →
Supports: Security considerations. Retrieved 2026-07-16.