Azure Integration built-in role
EventGrid EventSubscription Reader
Reads Event Grid event subscriptions without creating, updating, or deleting them. It contains control-plane read Actions only and does not create topics or publish events.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 2414bbcf-6497-4faf-8c65-045460748405
Control-plane actions (6)
Microsoft.Authorization/*/readMicrosoft.EventGrid/eventSubscriptions/readMicrosoft.EventGrid/topicTypes/eventSubscriptions/readMicrosoft.EventGrid/locations/eventSubscriptions/readMicrosoft.EventGrid/locations/topicTypes/eventSubscriptions/readMicrosoft.Resources/subscriptions/resourceGroups/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the Azure source resource, custom topic, or domain topic whose subscriptions the reviewer may inspect. Parent-scope assignments are inherited and expose subscriptions for additional sources below them.
Common use cases (2)
- Let an auditor or service owner inspect event routes and filters for one source resource or topic.
- Review event-domain topic subscriptions without granting tenant subscription changes.
Prerequisites (2)
- The event source and subscriptions to review must already exist.
- The reviewer must be approved to see destination and routing metadata for those subscriptions.
Best practices (2)
- Assign at the individual source or topic and elevate to EventSubscription Contributor only for an approved routing workflow.
- Review event destinations and filters periodically to identify stale or unexpected subscriptions.
Security considerations (2)
- Subscription metadata can reveal event sources, filters, and destination types even though the role cannot change the route.
- The role does not grant the dedicated full-endpoint URL action, topic management, or event publication.
Assignment guidance
Assign EventGrid EventSubscription Reader to reviewers on the specific source resource or topic. Use EventSubscription Contributor only when the principal must change routes and EventGrid Contributor only for broader resource administration.
Related roles (2)
- EventGrid EventSubscription Contributor: Adds event-subscription create, update, delete, and related management operations.
- EventGrid Contributor: Adds general Event Grid resource administration.
Editorial sources (6)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Authorizing access to Event Grid resources →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.