Azure Monitor built-in role
Grafana Viewer
Views an Azure Managed Grafana workspace, including its dashboards and alerts. The built-in role has no control-plane Actions and grants only the Grafana Viewer DataAction inside the assigned workspace.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 60921a7e-fef1-4a43-9b16-a26c52ad4769
Control-plane actions (0)
None — this role grants no control-plane management actions.
Data-plane actions (1)
Microsoft.Dashboard/grafana/ActAsGrafanaViewer/action
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual Azure Managed Grafana workspace. The Grafana role enables workspace viewing, while access to the underlying Azure monitoring data depends on the configured data-source identity and permissions.
Common use cases (2)
- Let operators or stakeholders view dashboards and alerts in one Azure Managed Grafana workspace without editing them.
- Allow a principal to query configured Grafana data sources within the authorization provided by those data sources.
Prerequisites (2)
- An Azure Managed Grafana workspace and a Microsoft Entra user, group, service principal, or managed identity are required.
- Configure Current User or managed-identity authorization for each data source and grant the corresponding identity access to the monitoring data.
Best practices (3)
- Use Viewer instead of Editor or Admin for users who only consume dashboards and alerts.
- Prefer Current User authentication where supported so the data source enforces each viewer's own Azure permissions.
- Use Limited Viewer plus explicit component permissions when workspace-wide viewing is too broad and the workspace version supports that role.
Security considerations (3)
- Viewer access can expose every dashboard and alert covered by the workspace's default permissions.
- The data available through a dashboard is governed by the data-source authentication configuration, which can use the current user or a shared managed identity.
- The role cannot edit dashboards or manage the Azure Managed Grafana resource control plane by itself.
Assignment guidance
Assign Grafana Viewer through Access control (IAM) on the specific Azure Managed Grafana resource. Configure data-source authorization separately and use Limited Viewer with explicit component permissions when the user should not see the whole workspace.
Related roles (2)
- Grafana Limited Viewer: Provides no component permissions by default for a more restricted supported workspace configuration.
- Grafana Editor: Adds dashboard and alert editing for approved authors.
Editorial sources (4)
- Azure built-in roles for Monitor →
Supports: Description, Practical scope, Common use cases, Security considerations. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Manage access and permissions for users and identities →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Secure Azure Managed Grafana →
Supports: Practical scope, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.