Azure Monitor built-in role
Monitoring Contributor
Views monitoring data and creates or changes monitoring settings without granting general resource modification. The published role uses control-plane Actions and has no DataActions, although some Actions expose shared keys or configure where monitoring data is collected and sent.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 749f88d5-cbae-40b8-bcfc-e573ddc772fa
Control-plane actions (46)
*/readMicrosoft.AlertsManagement/alerts/*Microsoft.AlertsManagement/alertsSummary/*Microsoft.AlertsManagement/issues/*Microsoft.Insights/actiongroups/*Microsoft.Insights/activityLogAlerts/*Microsoft.Insights/AlertRules/*Microsoft.Insights/components/*Microsoft.Insights/createNotifications/*Microsoft.Insights/dataCollectionEndpoints/*Microsoft.Insights/dataCollectionRules/*Microsoft.Insights/dataCollectionRuleAssociations/*Microsoft.Insights/DiagnosticSettings/*Microsoft.Insights/eventtypes/*Microsoft.Insights/LogDefinitions/*Microsoft.Insights/metricalerts/*Microsoft.Insights/MetricDefinitions/*Microsoft.Insights/Metrics/*Microsoft.Insights/notificationStatus/*Microsoft.Insights/Register/ActionMicrosoft.Insights/scheduledqueryrules/*Microsoft.Insights/webtests/*Microsoft.Insights/workbooks/*Microsoft.Insights/workbooktemplates/*Microsoft.Insights/privateLinkScopes/*Microsoft.Insights/privateLinkScopeOperationStatuses/*Microsoft.Monitor/accounts/*Microsoft.Monitor/settings/*Microsoft.OperationalInsights/workspaces/writeMicrosoft.OperationalInsights/workspaces/intelligencepacks/*Microsoft.OperationalInsights/workspaces/savedSearches/*Microsoft.OperationalInsights/workspaces/search/actionMicrosoft.OperationalInsights/workspaces/sharedKeys/actionMicrosoft.OperationalInsights/workspaces/sharedKeys/readMicrosoft.OperationalInsights/workspaces/storageinsightconfigs/*Microsoft.OperationalInsights/locations/workspaces/failover/actionMicrosoft.OperationalInsights/workspaces/failback/actionMicrosoft.Support/*Microsoft.AlertsManagement/smartDetectorAlertRules/*Microsoft.AlertsManagement/actionRules/*Microsoft.AlertsManagement/smartGroups/*Microsoft.AlertsManagement/migrateFromSmartDetection/*Microsoft.AlertsManagement/investigations/*Microsoft.AlertsManagement/prometheusRuleGroups/*Microsoft.Monitor/investigations/*Microsoft.Resources/deployments/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at a resource, resource group, or subscription according to the monitoring estate the principal must manage. The role is inherited by child resources, and broader scopes expand both visibility and monitoring-configuration authority.
Common use cases (2)
- Create and edit diagnostic settings and alert rules for approved Azure resources.
- Manage saved searches, workspace storage configuration, web tests, and Application Insights components for a monitoring team.
Prerequisites (2)
- The principal needs read access to the monitored resource type and scope for alerts, metrics, and diagnostic settings.
- Creating a diagnostic setting that sends to a storage account or event hub requires separate ListKeys permission on that destination.
Best practices (3)
- Assign the role at the smallest resource group or resource scope containing the monitoring resources it must manage.
- Keep monitoring storage accounts and event hubs in dedicated resource groups and grant destination key permissions only at those narrow scopes.
- Use Monitoring Reader for support or operations users who do not change monitoring settings.
Security considerations (3)
- Monitoring settings control alerting and telemetry routing, so changes can suppress notifications or redirect monitoring data.
- Workspace shared keys and separately granted storage or event-hub keys can authorize access beyond the role's lack of DataActions.
- The role does not itself read monitoring data already streamed to a storage account or event hub; those resources require separate access.
Assignment guidance
Assign Monitoring Contributor at the narrowest resource or dedicated monitoring resource-group scope that contains the settings to manage. Grant destination ListKeys permissions separately and only where diagnostic routing requires them.
Related roles (1)
- Monitoring Reader: Microsoft documents Monitoring Contributor as a superset of Monitoring Reader for principals who also change monitoring settings.
Editorial sources (5)
- Azure built-in roles for Monitor →
Supports: Description, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Roles, permissions, and security in Azure Monitor →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.