Azure Monitor built-in role

Log Analytics Contributor

Reads monitoring data and administers Log Analytics and related monitoring settings. The published definition combines broad control-plane Actions with a Log Analytics data-export DataAction, so it is broader than a workspace configuration role and broader than a query-only data reader.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 92aaf0da-9dab-42b6-94a3-d43ce8d16293

Control-plane actions (13)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on a workspace for workspace-specific administration. Some documented operations, including Automation accounts, management solutions, resource diagnostics, and VM extensions, require resource-group or subscription scope and therefore reach resources outside the workspace.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Log Analytics Contributor at the workspace for workspace administration. Use a broader scope only for a reviewed workflow that needs resource diagnostics, VM extensions, Automation, or solutions, and choose Reader or Data Reader for query-only access.

Related roles (2)

Common questions

When should I assign the Log Analytics Contributor Azure role?

Assign Log Analytics Contributor when you need to: Configure a Log Analytics workspace, its saved searches, data export, search jobs, restored logs, and monitoring solutions.; and Configure diagnostic collection or monitoring extensions on approved Azure resources when the full documented role boundary is required.. Practical scope: Assign on a workspace for workspace-specific administration. Some documented operations, including Automation accounts, management solutions, resource diagnostics, and VM extensions, require resource-group or subscription scope and therefore reach resources outside the workspace.

What permissions does the Log Analytics Contributor Azure role grant?

The role definition grants 14 combined control-plane and data-plane actions. Representative operations include: */read; Microsoft.ClassicCompute/virtualMachines/extensions/*; Microsoft.ClassicStorage/storageAccounts/listKeys/action; Microsoft.Compute/virtualMachines/extensions/*; Microsoft.HybridCompute/machines/extensions/write; and Microsoft.Insights/alertRules/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Log Analytics Contributor Azure role?

Key considerations when assigning Log Analytics Contributor: Microsoft warns that permission to add a virtual machine extension can be used to gain full control over a virtual machine.; The role can read storage account keys, configure data collection, restore retained data, and export workspace data.; and Its data-export DataAction moves log data beyond query access, while its broad Actions can change monitoring configuration across the assigned scope.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →