Azure Monitor built-in role
Azure Managed Grafana Workspace Contributor
Manages the Azure Resource Manager resource for an Azure Managed Grafana workspace without granting access inside the Grafana workspace. It is a control-plane role with Actions for workspace and private-endpoint management and has no Grafana DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 5c2d7e57-b7c2-4d8a-be4f-82afa42c6e95
Control-plane actions (35)
Microsoft.Dashboard/grafana/writeMicrosoft.Dashboard/grafana/deleteMicrosoft.Dashboard/grafana/PrivateEndpointConnectionsApproval/actionMicrosoft.Dashboard/grafana/managedPrivateEndpoints/actionMicrosoft.Dashboard/locations/operationStatuses/writeMicrosoft.Dashboard/grafana/privateEndpointConnectionProxies/validate/actionMicrosoft.Dashboard/grafana/privateEndpointConnectionProxies/writeMicrosoft.Dashboard/grafana/privateEndpointConnectionProxies/deleteMicrosoft.Dashboard/grafana/privateEndpointConnections/writeMicrosoft.Dashboard/grafana/privateEndpointConnections/deleteMicrosoft.Dashboard/grafana/managedPrivateEndpoints/writeMicrosoft.Dashboard/grafana/managedPrivateEndpoints/deleteMicrosoft.Dashboard/grafana/integrationFabrics/writeMicrosoft.Dashboard/grafana/integrationFabrics/deleteMicrosoft.Dashboard/grafana/grafanaDefinitions/readMicrosoft.Dashboard/grafana/grafanaDefinitions/writeMicrosoft.Dashboard/grafana/grafanaDefinitions/deleteMicrosoft.Authorization/*/readMicrosoft.Insights/AlertRules/WriteMicrosoft.Insights/AlertRules/DeleteMicrosoft.Insights/AlertRules/ReadMicrosoft.Insights/AlertRules/Activated/ActionMicrosoft.Insights/AlertRules/Resolved/ActionMicrosoft.Insights/AlertRules/Throttled/ActionMicrosoft.Insights/AlertRules/Incidents/ReadMicrosoft.Resources/deployments/readMicrosoft.Resources/deployments/writeMicrosoft.Resources/deployments/deleteMicrosoft.Resources/deployments/cancel/actionMicrosoft.Resources/deployments/validate/actionMicrosoft.Resources/deployments/whatIf/actionMicrosoft.Resources/deployments/exportTemplate/actionMicrosoft.Resources/deployments/operations/readMicrosoft.Resources/deployments/operationstatuses/readMicrosoft.Resources/subscriptions/resourceGroups/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the Azure Managed Grafana resource or its dedicated resource group. A parent assignment is inherited by every workspace below it; access to the Grafana user interface requires a separate Grafana data-plane role on each workspace.
Common use cases (2)
- Operate the Azure Managed Grafana resource lifecycle and its documented private connectivity configuration without receiving Grafana user-interface access.
- Separate platform ownership of a Grafana workspace resource from dashboard, data-source, and Grafana access administration.
Prerequisites (2)
- An Azure Managed Grafana workspace or an approved workspace deployment must be in the selected scope.
- Grant a separate Grafana Admin, Editor, Limited Viewer, or Viewer role when the same principal also needs to enter the Grafana user interface.
Best practices (3)
- Keep control-plane workspace management separate from Grafana user access and assign both only when the same principal requires both responsibilities.
- Use private endpoints and disable public network access for production workspaces when the documented trade-offs are acceptable.
- Review inherited resource-group assignments so one workspace operator does not manage unrelated Grafana workspaces.
Security considerations (3)
- The role can change or delete the Azure Managed Grafana resource and manage its private endpoint configuration, even though it cannot act inside Grafana.
- Network configuration changes can alter how users and data sources reach the workspace; public access is enabled by default on new workspaces unless it is explicitly disabled.
- A Grafana UI role and data-source authorization are separate grants and can materially expand the principal's effective access.
Assignment guidance
Assign Azure Managed Grafana Workspace Contributor at the individual workspace or its dedicated resource group to the platform operator. Grant a Grafana data-plane role separately at the workspace resource only when UI access is also required.
Related roles (3)
- Grafana Admin: Grafana Admin is the separate data-plane role Microsoft documents for full operations inside the Grafana workspace.
- Grafana Editor: Grafana Editor is the separate data-plane role for dashboard and alert editing without workspace-resource management.
- Grafana Viewer: Grafana Viewer is the separate data-plane role for viewing the Grafana workspace.
Editorial sources (7)
- Azure built-in roles for Monitor →
Supports: Description, Practical scope, Common use cases, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-16.
- Quickstart: Create an Azure Managed Grafana workspace using the Azure portal →
Supports: Prerequisites. Retrieved 2026-07-16.
- Manage access and permissions for users and identities →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Secure Azure Managed Grafana →
Supports: Common use cases, Best practices, Security considerations. Retrieved 2026-07-16.