Azure Monitor built-in role

Grafana Editor

Views and edits a Grafana instance, including dashboards and alerts. The built-in role has no control-plane Actions and grants only the Grafana Editor DataAction inside the assigned Azure Managed Grafana workspace.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: a79a5197-3a5c-4973-a920-486035ffd60f

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Azure Managed Grafana workspace. Its default Grafana permission applies across the workspace unless dashboard or folder permissions are refined in Grafana.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Grafana Editor on the specific Azure Managed Grafana resource to dashboard authors. Refine dashboard or folder permissions where needed and grant data-source access separately; use Grafana Admin only for administrative duties.

Related roles (2)

Common questions

When should I assign the Grafana Editor Azure role?

Assign Grafana Editor when you need to: Let a dashboard author create and modify dashboards and alerts without granting Grafana administrative access.; and Let a monitoring team maintain folders, dashboards, and playlists in one Grafana workspace.. Practical scope: Assign on the individual Azure Managed Grafana workspace. Its default Grafana permission applies across the workspace unless dashboard or folder permissions are refined in Grafana.

What permissions does the Grafana Editor Azure role grant?

The role definition grants 1 combined control-plane and data-plane actions. Representative operations include: Microsoft.Dashboard/grafana/ActAsGrafanaEditor/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Grafana Editor Azure role?

Key considerations when assigning Grafana Editor: By default, an Editor can modify dashboards throughout the workspace, which can change shared operational views and alerts.; Dashboard queries can expose data available through the configured data-source identity; Grafana role assignment and data-source authorization are separate controls.; and The role cannot manage the Azure Managed Grafana resource control plane by itself.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (4)

Official Microsoft Learn documentation →