Azure Monitor built-in role

Monitoring Contributor

Views monitoring data and creates or changes monitoring settings without granting general resource modification. The published role uses control-plane Actions and has no DataActions, although some Actions expose shared keys or configure where monitoring data is collected and sent.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 749f88d5-cbae-40b8-bcfc-e573ddc772fa

Control-plane actions (46)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at a resource, resource group, or subscription according to the monitoring estate the principal must manage. The role is inherited by child resources, and broader scopes expand both visibility and monitoring-configuration authority.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Monitoring Contributor at the narrowest resource or dedicated monitoring resource-group scope that contains the settings to manage. Grant destination ListKeys permissions separately and only where diagnostic routing requires them.

Related roles (1)

Common questions

When should I assign the Monitoring Contributor Azure role?

Assign Monitoring Contributor when you need to: Create and edit diagnostic settings and alert rules for approved Azure resources.; and Manage saved searches, workspace storage configuration, web tests, and Application Insights components for a monitoring team.. Practical scope: Assign at a resource, resource group, or subscription according to the monitoring estate the principal must manage. The role is inherited by child resources, and broader scopes expand both visibility and monitoring-configuration authority.

What permissions does the Monitoring Contributor Azure role grant?

The role definition grants 46 combined control-plane and data-plane actions. Representative operations include: */read; Microsoft.AlertsManagement/alerts/*; Microsoft.AlertsManagement/alertsSummary/*; Microsoft.AlertsManagement/issues/*; Microsoft.Insights/actiongroups/*; and Microsoft.Insights/activityLogAlerts/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Monitoring Contributor Azure role?

Key considerations when assigning Monitoring Contributor: Monitoring settings control alerting and telemetry routing, so changes can suppress notifications or redirect monitoring data.; Workspace shared keys and separately granted storage or event-hub keys can authorize access beyond the role's lack of DataActions.; and The role does not itself read monitoring data already streamed to a storage account or event hub; those resources require separate access.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →