Azure Monitor built-in role

Azure Managed Grafana Workspace Contributor

Manages the Azure Resource Manager resource for an Azure Managed Grafana workspace without granting access inside the Grafana workspace. It is a control-plane role with Actions for workspace and private-endpoint management and has no Grafana DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 5c2d7e57-b7c2-4d8a-be4f-82afa42c6e95

Control-plane actions (35)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the Azure Managed Grafana resource or its dedicated resource group. A parent assignment is inherited by every workspace below it; access to the Grafana user interface requires a separate Grafana data-plane role on each workspace.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Azure Managed Grafana Workspace Contributor at the individual workspace or its dedicated resource group to the platform operator. Grant a Grafana data-plane role separately at the workspace resource only when UI access is also required.

Related roles (3)

Editorial sources (7)

Official Microsoft Learn documentation →