Azure Monitor built-in role

Grafana Limited Viewer

Maps to Grafana's No Basic Role and lets the principal reach the Grafana home page without component permissions by default. The Azure role contains only a Grafana data-plane DataAction, has no control-plane Actions, and is not available for Grafana v9 workspaces.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 41e04612-9dac-4699-a02b-c82ff2cc3fb5

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Azure Managed Grafana workspace, then grant explicit permissions to only the required dashboards, folders, and data sources inside Grafana. The role does not manage the Azure workspace resource.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

For a supported non-v9 workspace, assign Grafana Limited Viewer at the Azure Managed Grafana resource and then grant explicit permissions only to the approved dashboards, folders, and data sources. Use Grafana Viewer when workspace-wide viewing is intended.

Related roles (1)

Common questions

When should I assign the Grafana Limited Viewer Azure role?

Assign Grafana Limited Viewer when you need to: Onboard a user with no default dashboard or data-source permissions and grant access only to selected Grafana components.; and Provide a restricted starting point for a user who should see a small approved subset of one Grafana workspace.. Practical scope: Assign on the individual Azure Managed Grafana workspace, then grant explicit permissions to only the required dashboards, folders, and data sources inside Grafana. The role does not manage the Azure workspace resource.

What permissions does the Grafana Limited Viewer Azure role grant?

The role definition grants 1 combined control-plane and data-plane actions. Representative operations include: Microsoft.Dashboard/grafana/ActAsGrafanaLimitedViewer/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Grafana Limited Viewer Azure role?

Key considerations when assigning Grafana Limited Viewer: Effective access comes from the explicit component permissions added after the Azure role assignment, not from the Limited Viewer role alone.; Data-source authorization remains separate and determines which underlying monitoring data can be queried.; and Using this role on a Grafana v9 workspace is unsupported because Microsoft states that it is not available there.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →