Azure Integration built-in role

EventGrid EventSubscription Reader

Reads Event Grid event subscriptions without creating, updating, or deleting them. It contains control-plane read Actions only and does not create topics or publish events.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 2414bbcf-6497-4faf-8c65-045460748405

Control-plane actions (6)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the Azure source resource, custom topic, or domain topic whose subscriptions the reviewer may inspect. Parent-scope assignments are inherited and expose subscriptions for additional sources below them.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign EventGrid EventSubscription Reader to reviewers on the specific source resource or topic. Use EventSubscription Contributor only when the principal must change routes and EventGrid Contributor only for broader resource administration.

Related roles (2)

Common questions

When should I assign the EventGrid EventSubscription Reader Azure role?

Assign EventGrid EventSubscription Reader when you need to: Let an auditor or service owner inspect event routes and filters for one source resource or topic.; and Review event-domain topic subscriptions without granting tenant subscription changes.. Practical scope: Assign on the Azure source resource, custom topic, or domain topic whose subscriptions the reviewer may inspect. Parent-scope assignments are inherited and expose subscriptions for additional sources below them.

What permissions does the EventGrid EventSubscription Reader Azure role grant?

The role definition grants 6 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.EventGrid/eventSubscriptions/read; Microsoft.EventGrid/topicTypes/eventSubscriptions/read; Microsoft.EventGrid/locations/eventSubscriptions/read; Microsoft.EventGrid/locations/topicTypes/eventSubscriptions/read; and Microsoft.Resources/subscriptions/resourceGroups/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the EventGrid EventSubscription Reader Azure role?

Key considerations when assigning EventGrid EventSubscription Reader: Subscription metadata can reveal event sources, filters, and destination types even though the role cannot change the route.; and The role does not grant the dedicated full-endpoint URL action, topic management, or event publication.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →