Azure Monitor built-in role
Grafana Limited Viewer
Maps to Grafana's No Basic Role and lets the principal reach the Grafana home page without component permissions by default. The Azure role contains only a Grafana data-plane DataAction, has no control-plane Actions, and is not available for Grafana v9 workspaces.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 41e04612-9dac-4699-a02b-c82ff2cc3fb5
Control-plane actions (0)
None — this role grants no control-plane management actions.
Data-plane actions (1)
Microsoft.Dashboard/grafana/ActAsGrafanaLimitedViewer/action
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual Azure Managed Grafana workspace, then grant explicit permissions to only the required dashboards, folders, and data sources inside Grafana. The role does not manage the Azure workspace resource.
Common use cases (2)
- Onboard a user with no default dashboard or data-source permissions and grant access only to selected Grafana components.
- Provide a restricted starting point for a user who should see a small approved subset of one Grafana workspace.
Prerequisites (2)
- The Azure Managed Grafana workspace must support Grafana Limited Viewer; Microsoft states that the role is unavailable for Grafana v9 workspaces.
- An administrator must grant explicit dashboard, folder, or data-source permissions because the role contains no component permissions by default.
Best practices (3)
- Use Limited Viewer as the default for restricted new users, then add only the component permissions they need.
- Review explicit dashboard and data-source grants because the base role alone does not describe the user's effective access.
- Use Microsoft Entra groups and Grafana teams when those mappings make restricted component access easier to manage.
Security considerations (3)
- Effective access comes from the explicit component permissions added after the Azure role assignment, not from the Limited Viewer role alone.
- Data-source authorization remains separate and determines which underlying monitoring data can be queried.
- Using this role on a Grafana v9 workspace is unsupported because Microsoft states that it is not available there.
Assignment guidance
For a supported non-v9 workspace, assign Grafana Limited Viewer at the Azure Managed Grafana resource and then grant explicit permissions only to the approved dashboards, folders, and data sources. Use Grafana Viewer when workspace-wide viewing is intended.
Related roles (1)
- Grafana Viewer: Viewer supplies the documented workspace-wide view experience, while Limited Viewer starts with no component permissions by default.
Editorial sources (5)
- Azure built-in roles for Monitor →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Manage access and permissions for users and identities →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Secure Azure Managed Grafana →
Supports: Best practices, Security considerations. Retrieved 2026-07-16.