Azure Monitor built-in role

Grafana Viewer

Views an Azure Managed Grafana workspace, including its dashboards and alerts. The built-in role has no control-plane Actions and grants only the Grafana Viewer DataAction inside the assigned workspace.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 60921a7e-fef1-4a43-9b16-a26c52ad4769

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Azure Managed Grafana workspace. The Grafana role enables workspace viewing, while access to the underlying Azure monitoring data depends on the configured data-source identity and permissions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Grafana Viewer through Access control (IAM) on the specific Azure Managed Grafana resource. Configure data-source authorization separately and use Limited Viewer with explicit component permissions when the user should not see the whole workspace.

Related roles (2)

Common questions

When should I assign the Grafana Viewer Azure role?

Assign Grafana Viewer when you need to: Let operators or stakeholders view dashboards and alerts in one Azure Managed Grafana workspace without editing them.; and Allow a principal to query configured Grafana data sources within the authorization provided by those data sources.. Practical scope: Assign on the individual Azure Managed Grafana workspace. The Grafana role enables workspace viewing, while access to the underlying Azure monitoring data depends on the configured data-source identity and permissions.

What permissions does the Grafana Viewer Azure role grant?

The role definition grants 1 combined control-plane and data-plane actions. Representative operations include: Microsoft.Dashboard/grafana/ActAsGrafanaViewer/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Grafana Viewer Azure role?

Key considerations when assigning Grafana Viewer: Viewer access can expose every dashboard and alert covered by the workspace's default permissions.; The data available through a dashboard is governed by the data-source authentication configuration, which can use the current user or a shared managed identity.; and The role cannot edit dashboards or manage the Azure Managed Grafana resource control plane by itself.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (4)

Official Microsoft Learn documentation →