Azure Identity built-in role

Domain Services Reader

Views Microsoft Entra Domain Services managed domains and related Azure network, deployment, monitoring, and diagnostic configuration without changing those resources.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 361898ef-9ed1-48c2-849c-a832951106bb

Control-plane actions (28)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The built-in definition is available throughout the Azure hierarchy. The assignment applies at the selected scope and inherited child scopes. Its permissions are read-oriented control-plane Actions across Domain Services and related resources; it has no DataActions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Domain Services Reader for view-only operations and troubleshooting at the smallest scope that includes the managed domain and the related network resources the principal must inspect. Escalate to Domain Services Contributor only for an approved change task.

Related roles (1)

Editorial sources (4)

Official Microsoft Learn documentation →