Azure Security built-in role
Microsoft Sentinel Reader
Views Microsoft Sentinel data, incidents, workbooks, recommendations, analytics configuration, and other workspace resources without managing Sentinel incidents or content. Despite the Reader name, its generic control-plane Actions can create and manage classic metric alerts, deployments, and support tickets. The definition excludes ConfidentialWatchlists and has no DataActions, while still allowing documented workspace queries and threat-intelligence query operations.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 8d289c81-5878-46d4-8554-54e1e3d8b5cb
Control-plane actions (21)
Microsoft.SecurityInsights/*/readMicrosoft.SecurityInsights/dataConnectorsCheckRequirements/actionMicrosoft.SecurityInsights/threatIntelligence/indicators/query/actionMicrosoft.SecurityInsights/threatIntelligence/queryIndicators/actionMicrosoft.OperationalInsights/workspaces/analytics/query/actionMicrosoft.OperationalInsights/workspaces/*/readMicrosoft.OperationalInsights/workspaces/LinkedServices/readMicrosoft.OperationalInsights/workspaces/savedSearches/readMicrosoft.OperationsManagement/solutions/readMicrosoft.OperationalInsights/workspaces/query/readMicrosoft.OperationalInsights/workspaces/query/*/readMicrosoft.OperationalInsights/querypacks/*/readMicrosoft.OperationalInsights/workspaces/dataSources/readMicrosoft.Insights/workbooks/readMicrosoft.Insights/myworkbooks/readMicrosoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/templateSpecs/*/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (2)
Microsoft.SecurityInsights/ConfidentialWatchlists/*Microsoft.OperationalInsights/workspaces/query/ConfidentialWatchlist/*
Assignable scopes (1)
/
Practical scope
Microsoft recommends assigning the role at the resource group containing the Sentinel workspace. A workspace-only assignment also requires the same role on the SecurityInsights solution and can require continuing assignments on related resources. Parent-scope access is inherited by all child workspaces and extends the classic-alert, deployment, and support Actions across that parent scope.
Common use cases (2)
- Give SOC observers, auditors, threat hunters, or support personnel view access to Sentinel incidents, data, workbooks, and recommendations.
- Run the documented interactive workspace queries and inspect analytics or connector configuration without changing it.
Prerequisites (3)
- Identify the Sentinel workspace and determine whether the principal is authorized to view its security logs and incident evidence.
- Confirm that incident updates, playbook execution, and content changes are not required.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at the Sentinel resource-group scope.
Best practices (3)
- Use Reader for users who must view Sentinel workspace data but do not manage Sentinel incidents or content, and account for its ancillary control-plane writes at the chosen scope.
- Use resource-context or table-level RBAC when a team must see only selected data rather than the whole workspace.
- Review cumulative Azure, Log Analytics, Microsoft Entra, and Sentinel roles because their permissions add together.
Security considerations (3)
- Read access can expose security logs, incidents, entities, threat intelligence, workbook content, and infrastructure details.
- The built-in definition explicitly excludes ConfidentialWatchlists, so this role must not be represented as access to that protected content.
- The role cannot manage Sentinel incidents or content, but it can create and manage classic metric alerts, deployments, and support tickets at the assignment scope.
Assignment guidance
Assign Microsoft Sentinel Reader at the Sentinel resource group for users who need workspace security visibility without Sentinel incident or content changes. Review its classic-alert, deployment, and support Actions at that scope; use Responder for incident management and Contributor for detection, content, and automation engineering.
Related roles (2)
- Microsoft Sentinel Responder: Microsoft documents Responder as all Reader permissions plus incident management.
- Microsoft Sentinel Contributor: Microsoft documents Contributor as all Responder permissions plus Sentinel resource and content management.
Editorial sources (5)
- Azure built-in roles for Security →
Supports: Description, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Roles and permissions in the Microsoft Sentinel platform →
Supports: Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.