Azure Monitor built-in role

Grafana Admin

Performs all Grafana operations in an Azure Managed Grafana workspace, including managing data sources, dashboards, and role assignments inside Grafana. The built-in role has no control-plane Actions and grants only the Grafana Admin DataAction.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 22926164-76b3-42b3-bc55-97df8dab3e41

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Azure Managed Grafana workspace. The DataAction authorizes the principal to act inside that Grafana instance; it does not manage the Azure Resource Manager workspace resource.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Grafana Admin through Access control (IAM) on the specific Azure Managed Grafana resource only to principals responsible for Grafana security, data sources, and workspace-wide configuration. Use Editor, Viewer, or Limited Viewer for narrower duties.

Related roles (2)

Common questions

When should I assign the Grafana Admin Azure role?

Assign Grafana Admin when you need to: Administer Grafana data sources, dashboards, alerts, users, teams, and role assignments for one Azure Managed Grafana workspace.; and Configure component permissions or Team Sync when full Grafana administration is required.. Practical scope: Assign on the individual Azure Managed Grafana workspace. The DataAction authorizes the principal to act inside that Grafana instance; it does not manage the Azure Resource Manager workspace resource.

What permissions does the Grafana Admin Azure role grant?

The role definition grants 1 combined control-plane and data-plane actions. Representative operations include: Microsoft.Dashboard/grafana/ActAsGrafanaAdmin/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Grafana Admin Azure role?

Key considerations when assigning Grafana Admin: Grafana Admin can change data sources, workspace security settings, and access assignments inside Grafana.; Data-source configuration can expose monitoring data according to the authentication method and permissions configured for that source.; and This data-plane role does not grant control-plane workspace management; combining it with Workspace Contributor expands authority across both planes.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →