Azure Monitor built-in role
Monitored Objects Contributor
Grants permissions to create and link a monitored object to a user or group. For more information, see Set up the Azure Monitor Agent on Windows client devices.
Control-plane and data-plane permissions below are imported directly from Microsoft Learn. In-app editorial guidance (use cases, best practices, security notes) and least-privilege recommendations are still pending review.
Role definition ID: 56be40e2-4db1-4ccf-93c3-7e44c597135b
Control-plane actions (3)
Microsoft.Authorization/*/readMicrosoft.Insights/monitoredObjects/*Microsoft.Resources/subscriptions/resourceGroups/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/