Azure Monitor built-in role

Grafana Admin

Performs all Grafana operations in an Azure Managed Grafana workspace, including managing data sources, dashboards, and role assignments inside Grafana. The built-in role has no control-plane Actions and grants only the Grafana Admin DataAction.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 22926164-76b3-42b3-bc55-97df8dab3e41

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Azure Managed Grafana workspace. The DataAction authorizes the principal to act inside that Grafana instance; it does not manage the Azure Resource Manager workspace resource.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Grafana Admin through Access control (IAM) on the specific Azure Managed Grafana resource only to principals responsible for Grafana security, data sources, and workspace-wide configuration. Use Editor, Viewer, or Limited Viewer for narrower duties.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →