Azure Monitor built-in role
Grafana Editor
Views and edits a Grafana instance, including dashboards and alerts. The built-in role has no control-plane Actions and grants only the Grafana Editor DataAction inside the assigned Azure Managed Grafana workspace.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: a79a5197-3a5c-4973-a920-486035ffd60f
Control-plane actions (0)
None — this role grants no control-plane management actions.
Data-plane actions (1)
Microsoft.Dashboard/grafana/ActAsGrafanaEditor/action
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual Azure Managed Grafana workspace. Its default Grafana permission applies across the workspace unless dashboard or folder permissions are refined in Grafana.
Common use cases (2)
- Let a dashboard author create and modify dashboards and alerts without granting Grafana administrative access.
- Let a monitoring team maintain folders, dashboards, and playlists in one Grafana workspace.
Prerequisites (2)
- An Azure Managed Grafana workspace and a Microsoft Entra user, group, service principal, or managed identity are required.
- The principal needs separate authorization to each underlying data source according to the selected data-source authentication method.
Best practices (3)
- Use Grafana Editor for dashboard authors instead of Grafana Admin when they do not manage data sources, users, or workspace security.
- Use dashboard and folder permissions or Team Sync when an editor should not modify every dashboard in the workspace.
- Prefer Current User authentication for supported data sources so each editor queries only data their own identity can access.
Security considerations (3)
- By default, an Editor can modify dashboards throughout the workspace, which can change shared operational views and alerts.
- Dashboard queries can expose data available through the configured data-source identity; Grafana role assignment and data-source authorization are separate controls.
- The role cannot manage the Azure Managed Grafana resource control plane by itself.
Assignment guidance
Assign Grafana Editor on the specific Azure Managed Grafana resource to dashboard authors. Refine dashboard or folder permissions where needed and grant data-source access separately; use Grafana Admin only for administrative duties.
Related roles (2)
- Grafana Admin: Adds data-source, access, and workspace-wide Grafana administration.
- Grafana Viewer: Read-oriented alternative for users who should view dashboards and alerts without editing them.
Editorial sources (4)
- Azure built-in roles for Monitor →
Supports: Description, Practical scope, Security considerations, Related roles. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Manage access and permissions for users and identities →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Secure Azure Managed Grafana →
Supports: Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.