Azure Monitor built-in role
Grafana Admin
Performs all Grafana operations in an Azure Managed Grafana workspace, including managing data sources, dashboards, and role assignments inside Grafana. The built-in role has no control-plane Actions and grants only the Grafana Admin DataAction.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 22926164-76b3-42b3-bc55-97df8dab3e41
Control-plane actions (0)
None — this role grants no control-plane management actions.
Data-plane actions (1)
Microsoft.Dashboard/grafana/ActAsGrafanaAdmin/action
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual Azure Managed Grafana workspace. The DataAction authorizes the principal to act inside that Grafana instance; it does not manage the Azure Resource Manager workspace resource.
Common use cases (2)
- Administer Grafana data sources, dashboards, alerts, users, teams, and role assignments for one Azure Managed Grafana workspace.
- Configure component permissions or Team Sync when full Grafana administration is required.
Prerequisites (2)
- An Azure Managed Grafana workspace and a Microsoft Entra user, group, service principal, or managed identity are required.
- Data sources need their own supported authentication and authorization; the Grafana Admin DataAction does not itself grant access to the underlying Azure data.
Best practices (3)
- Minimize the number of Grafana Admin assignments and use Grafana Editor for dashboard authors who do not need security or workspace configuration.
- Prefer Current User authentication for supported data sources and managed identity when Current User authentication is unavailable.
- Review guest users, dashboard permissions, service accounts, and administrative assignments regularly.
Security considerations (3)
- Grafana Admin can change data sources, workspace security settings, and access assignments inside Grafana.
- Data-source configuration can expose monitoring data according to the authentication method and permissions configured for that source.
- This data-plane role does not grant control-plane workspace management; combining it with Workspace Contributor expands authority across both planes.
Assignment guidance
Assign Grafana Admin through Access control (IAM) on the specific Azure Managed Grafana resource only to principals responsible for Grafana security, data sources, and workspace-wide configuration. Use Editor, Viewer, or Limited Viewer for narrower duties.
Related roles (2)
- Grafana Editor: Microsoft recommends Editor for power users who need to create and modify dashboards without Grafana administrative privileges.
- Azure Managed Grafana Workspace Contributor: Workspace Contributor manages the Azure resource control plane but does not provide access inside Grafana.
Editorial sources (6)
- Azure built-in roles for Monitor →
Supports: Description, Practical scope, Security considerations, Related roles. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Manage access and permissions for users and identities →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Secure Azure Managed Grafana →
Supports: Prerequisites, Best practices, Security considerations, Related roles. Retrieved 2026-07-16.