Azure Monitor built-in role

Log Analytics Reader

Views and searches monitoring data and monitoring settings across the assigned scope. The definition has broad control-plane read Actions, explicitly excludes reading workspace shared keys, and also publishes a Log Analytics data-export DataAction.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 73c42c96-874c-492b-b04d-ab87d138a893

Control-plane actions (4)

Data-plane actions (1)

Excluded actions (1)

Assignable scopes (1)

Practical scope

Assign on a workspace for workspace-context visibility or on a resource, resource group, or subscription for the intended inherited resource-context visibility. The workspace access control mode and query context determine which logs can be queried.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Log Analytics Reader at the workspace or narrow resource boundary for broad read access. Use Log Analytics Data Reader with conditions for granular data access and review the role's export capability before approval.

Related roles (2)

Common questions

When should I assign the Log Analytics Reader Azure role?

Assign Log Analytics Reader when you need to: Inspect Log Analytics data, workspace settings, resource configuration, and diagnostic settings without changing them.; and Support or audit monitoring across an approved scope when granular table- or row-level restrictions are not required.. Practical scope: Assign on a workspace for workspace-context visibility or on a resource, resource group, or subscription for the intended inherited resource-context visibility. The workspace access control mode and query context determine which logs can be queried.

What permissions does the Log Analytics Reader Azure role grant?

The role definition grants 5 combined control-plane and data-plane actions. Representative operations include: */read; Microsoft.OperationalInsights/workspaces/analytics/query/action; Microsoft.OperationalInsights/workspaces/search/action; Microsoft.Support/*; and Microsoft.OperationalInsights/workspaces/jobs/export/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Log Analytics Reader Azure role?

Key considerations when assigning Log Analytics Reader: The broad read Actions expose Azure resource configuration and monitoring settings throughout the assigned scope.; The role excludes workspace shared-key reads but still permits querying authorized monitoring data and includes a data-export DataAction.; and Workspace mode, resource permissions, protected-table settings, and other additive assignments all affect the data the principal can see.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →