Azure Security built-in role

Microsoft Sentinel Reader

Views Microsoft Sentinel data, incidents, workbooks, recommendations, analytics configuration, and other workspace resources without managing Sentinel incidents or content. Despite the Reader name, its generic control-plane Actions can create and manage classic metric alerts, deployments, and support tickets. The definition excludes ConfidentialWatchlists and has no DataActions, while still allowing documented workspace queries and threat-intelligence query operations.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 8d289c81-5878-46d4-8554-54e1e3d8b5cb

Control-plane actions (21)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (2)

Assignable scopes (1)

Practical scope

Microsoft recommends assigning the role at the resource group containing the Sentinel workspace. A workspace-only assignment also requires the same role on the SecurityInsights solution and can require continuing assignments on related resources. Parent-scope access is inherited by all child workspaces and extends the classic-alert, deployment, and support Actions across that parent scope.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Microsoft Sentinel Reader at the Sentinel resource group for users who need workspace security visibility without Sentinel incident or content changes. Review its classic-alert, deployment, and support Actions at that scope; use Responder for incident management and Contributor for detection, content, and automation engineering.

Related roles (2)

Editorial sources (5)

Official Microsoft Learn documentation →