Azure Identity built-in role
Domain Services Reader
Views Microsoft Entra Domain Services managed domains and related Azure network, deployment, monitoring, and diagnostic configuration without changing those resources.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 361898ef-9ed1-48c2-849c-a832951106bb
Control-plane actions (28)
Microsoft.Authorization/*/readMicrosoft.Resources/deployments/readMicrosoft.Resources/deployments/operations/readMicrosoft.Resources/deployments/operationstatuses/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Insights/AlertRules/ReadMicrosoft.Insights/AlertRules/Incidents/ReadMicrosoft.Insights/Logs/ReadMicrosoft.Insights/Metrics/readMicrosoft.Insights/DiagnosticSettings/readMicrosoft.Insights/DiagnosticSettingsCategories/ReadMicrosoft.AAD/domainServices/*/readMicrosoft.Network/virtualNetworks/readMicrosoft.Network/virtualNetworks/subnets/readMicrosoft.Network/virtualNetworks/virtualNetworkPeerings/readMicrosoft.Network/virtualNetworks/providers/Microsoft.Insights/diagnosticSettings/readMicrosoft.Network/virtualNetworks/providers/Microsoft.Insights/metricDefinitions/readMicrosoft.Network/azureFirewalls/readMicrosoft.Network/ddosProtectionPlans/readMicrosoft.Network/loadBalancers/readMicrosoft.Network/loadBalancers/*/readMicrosoft.Network/natGateways/readMicrosoft.Network/networkInterfaces/readMicrosoft.Network/networkSecurityGroups/defaultSecurityRules/readMicrosoft.Network/networkSecurityGroups/readMicrosoft.Network/networkSecurityGroups/securityRules/readMicrosoft.Network/routeTables/readMicrosoft.Network/routeTables/routes/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The built-in definition is available throughout the Azure hierarchy. The assignment applies at the selected scope and inherited child scopes. Its permissions are read-oriented control-plane Actions across Domain Services and related resources; it has no DataActions.
Common use cases (2)
- Inspect managed-domain status and configuration without making changes.
- Review related virtual-network, subnet, security-rule, route, deployment, metric, log, and diagnostic configuration for troubleshooting or audit work.
Prerequisites (2)
- Identify the managed domain and related network scope the principal must inspect.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at that scope.
Best practices (3)
- Use this role instead of Domain Services Contributor for inspection, audit, and troubleshooting tasks that require no changes.
- Scope the assignment to the resource group or other boundary containing the managed domain and approved dependencies.
- Review broad assignments because read access inherited from a parent can expose configuration for multiple managed domains and networks.
Security considerations (3)
- Read-only access includes managed-domain, network, deployment, metric, log, and diagnostic metadata that can reveal environment topology.
- The role cannot change the listed resources and has no DataActions, but broad inherited visibility can still be sensitive.
- This Azure role does not grant Microsoft Entra directory administration.
Assignment guidance
Assign Domain Services Reader for view-only operations and troubleshooting at the smallest scope that includes the managed domain and the related network resources the principal must inspect. Escalate to Domain Services Contributor only for an approved change task.
Related roles (1)
- Domain Services Contributor: Adds managed-domain and related network changes when read-only access is insufficient.
Common questions
When should I assign the Domain Services Reader Azure role?
Assign Domain Services Reader when you need to: Inspect managed-domain status and configuration without making changes.; and Review related virtual-network, subnet, security-rule, route, deployment, metric, log, and diagnostic configuration for troubleshooting or audit work.. Practical scope: The built-in definition is available throughout the Azure hierarchy. The assignment applies at the selected scope and inherited child scopes. Its permissions are read-oriented control-plane Actions across Domain Services and related resources; it has no DataActions.
What permissions does the Domain Services Reader Azure role grant?
The role definition grants 28 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Resources/deployments/read; Microsoft.Resources/deployments/operations/read; Microsoft.Resources/deployments/operationstatuses/read; Microsoft.Resources/subscriptions/resourceGroups/read; and Microsoft.Insights/AlertRules/Read. Review the permission sections above for the complete definition and exclusions.
What are the security risks of the Domain Services Reader Azure role?
Key considerations when assigning Domain Services Reader: Read-only access includes managed-domain, network, deployment, metric, log, and diagnostic metadata that can reveal environment topology.; The role cannot change the listed resources and has no DataActions, but broad inherited visibility can still be sensitive.; and This Azure role does not grant Microsoft Entra directory administration.. Follow the assignment guidance above and use the narrowest practical scope.
Editorial sources (4)
- Azure built-in roles for Identity →
Supports: Description, Practical scope, Common use cases, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites. Retrieved 2026-07-16.
- Azure roles, Microsoft Entra roles, and classic subscription administrator roles →
Supports: Security considerations. Retrieved 2026-07-16.