Azure Integration built-in role
EventGrid EventSubscription Reader
Reads Event Grid event subscriptions without creating, updating, or deleting them. It contains control-plane read Actions only and does not create topics or publish events.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 2414bbcf-6497-4faf-8c65-045460748405
Control-plane actions (6)
Microsoft.Authorization/*/readMicrosoft.EventGrid/eventSubscriptions/readMicrosoft.EventGrid/topicTypes/eventSubscriptions/readMicrosoft.EventGrid/locations/eventSubscriptions/readMicrosoft.EventGrid/locations/topicTypes/eventSubscriptions/readMicrosoft.Resources/subscriptions/resourceGroups/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the Azure source resource, custom topic, or domain topic whose subscriptions the reviewer may inspect. Parent-scope assignments are inherited and expose subscriptions for additional sources below them.
Common use cases (2)
- Let an auditor or service owner inspect event routes and filters for one source resource or topic.
- Review event-domain topic subscriptions without granting tenant subscription changes.
Prerequisites (2)
- The event source and subscriptions to review must already exist.
- The reviewer must be approved to see destination and routing metadata for those subscriptions.
Best practices (2)
- Assign at the individual source or topic and elevate to EventSubscription Contributor only for an approved routing workflow.
- Review event destinations and filters periodically to identify stale or unexpected subscriptions.
Security considerations (2)
- Subscription metadata can reveal event sources, filters, and destination types even though the role cannot change the route.
- The role does not grant the dedicated full-endpoint URL action, topic management, or event publication.
Assignment guidance
Assign EventGrid EventSubscription Reader to reviewers on the specific source resource or topic. Use EventSubscription Contributor only when the principal must change routes and EventGrid Contributor only for broader resource administration.
Related roles (2)
- EventGrid EventSubscription Contributor: Adds event-subscription create, update, delete, and related management operations.
- EventGrid Contributor: Adds general Event Grid resource administration.
Common questions
When should I assign the EventGrid EventSubscription Reader Azure role?
Assign EventGrid EventSubscription Reader when you need to: Let an auditor or service owner inspect event routes and filters for one source resource or topic.; and Review event-domain topic subscriptions without granting tenant subscription changes.. Practical scope: Assign on the Azure source resource, custom topic, or domain topic whose subscriptions the reviewer may inspect. Parent-scope assignments are inherited and expose subscriptions for additional sources below them.
What permissions does the EventGrid EventSubscription Reader Azure role grant?
The role definition grants 6 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.EventGrid/eventSubscriptions/read; Microsoft.EventGrid/topicTypes/eventSubscriptions/read; Microsoft.EventGrid/locations/eventSubscriptions/read; Microsoft.EventGrid/locations/topicTypes/eventSubscriptions/read; and Microsoft.Resources/subscriptions/resourceGroups/read. Review the permission sections above for the complete definition and exclusions.
What are the security risks of the EventGrid EventSubscription Reader Azure role?
Key considerations when assigning EventGrid EventSubscription Reader: Subscription metadata can reveal event sources, filters, and destination types even though the role cannot change the route.; and The role does not grant the dedicated full-endpoint URL action, topic management, or event publication.. Follow the assignment guidance above and use the narrowest practical scope.
Editorial sources (6)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Authorizing access to Event Grid resources →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.