Azure Monitor built-in role

Log Analytics Reader

Views and searches monitoring data and monitoring settings across the assigned scope. The definition has broad control-plane read Actions, explicitly excludes reading workspace shared keys, and also publishes a Log Analytics data-export DataAction.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 73c42c96-874c-492b-b04d-ab87d138a893

Control-plane actions (4)

Data-plane actions (1)

Excluded actions (1)

Assignable scopes (1)

Practical scope

Assign on a workspace for workspace-context visibility or on a resource, resource group, or subscription for the intended inherited resource-context visibility. The workspace access control mode and query context determine which logs can be queried.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Log Analytics Reader at the workspace or narrow resource boundary for broad read access. Use Log Analytics Data Reader with conditions for granular data access and review the role's export capability before approval.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →