Azure Monitor built-in role

Azure Managed Grafana Workspace Contributor

Manages the Azure Resource Manager resource for an Azure Managed Grafana workspace without granting access inside the Grafana workspace. It is a control-plane role with Actions for workspace and private-endpoint management and has no Grafana DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 5c2d7e57-b7c2-4d8a-be4f-82afa42c6e95

Control-plane actions (35)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the Azure Managed Grafana resource or its dedicated resource group. A parent assignment is inherited by every workspace below it; access to the Grafana user interface requires a separate Grafana data-plane role on each workspace.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Azure Managed Grafana Workspace Contributor at the individual workspace or its dedicated resource group to the platform operator. Grant a Grafana data-plane role separately at the workspace resource only when UI access is also required.

Related roles (3)

Common questions

When should I assign the Azure Managed Grafana Workspace Contributor Azure role?

Assign Azure Managed Grafana Workspace Contributor when you need to: Operate the Azure Managed Grafana resource lifecycle and its documented private connectivity configuration without receiving Grafana user-interface access.; and Separate platform ownership of a Grafana workspace resource from dashboard, data-source, and Grafana access administration.. Practical scope: Assign on the Azure Managed Grafana resource or its dedicated resource group. A parent assignment is inherited by every workspace below it; access to the Grafana user interface requires a separate Grafana data-plane role on each workspace.

What permissions does the Azure Managed Grafana Workspace Contributor Azure role grant?

The role definition grants 35 combined control-plane and data-plane actions. Representative operations include: Microsoft.Dashboard/grafana/write; Microsoft.Dashboard/grafana/delete; Microsoft.Dashboard/grafana/PrivateEndpointConnectionsApproval/action; Microsoft.Dashboard/grafana/managedPrivateEndpoints/action; Microsoft.Dashboard/locations/operationStatuses/write; and Microsoft.Dashboard/grafana/privateEndpointConnectionProxies/validate/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure Managed Grafana Workspace Contributor Azure role?

Key considerations when assigning Azure Managed Grafana Workspace Contributor: The role can change or delete the Azure Managed Grafana resource and manage its private endpoint configuration, even though it cannot act inside Grafana.; Network configuration changes can alter how users and data sources reach the workspace; public access is enabled by default on new workspaces unless it is explicitly disabled.; and A Grafana UI role and data-source authorization are separate grants and can materially expand the principal's effective access.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →