Azure Monitor built-in role
Monitoring Reader
Views monitoring data and monitoring settings without changing monitored resources or monitoring configuration. The published definition uses broad control-plane read Actions and has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 43d0d8ad-25c7-4714-9337-8ba259a9fe05
Control-plane actions (3)
*/readMicrosoft.OperationalInsights/workspaces/search/actionMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at a resource, resource group, or subscription according to the monitoring data the principal must inspect. The broad control-plane read permission is inherited by all child resources in the selected scope.
Common use cases (2)
- View monitoring dashboards, alert rules, metrics, Activity Log records, diagnostic settings, autoscale settings, and Application Insights data.
- Query authorized Log Analytics data and retrieve workspace table schemas and saved queries for support or operations work.
Prerequisites (2)
- Identify the resources whose monitoring data the principal must inspect and choose the narrowest scope containing them.
- Grant separate access when the investigation needs monitoring data that was streamed to an event hub or stored in a storage account.
Best practices (3)
- Use resource or dedicated monitoring resource-group scope instead of subscription scope when cross-subscription visibility is unnecessary.
- Keep monitoring storage accounts and event hubs in separate scopes and grant their data access independently.
- Use Monitoring Contributor only when the principal must change monitoring settings.
Security considerations (3)
- The role's control-plane read permission exposes resource configuration and monitoring metadata throughout the assigned scope.
- Monitoring data can contain sensitive information such as IP addresses and user names.
- The role does not itself grant read access to monitoring data stored in a storage account or streamed to an event hub.
Assignment guidance
Assign Monitoring Reader at the smallest resource or resource-group scope that covers the monitoring investigation. Add storage, event-hub, or other data access separately only when the task requires those destinations.
Related roles (1)
- Monitoring Contributor: Microsoft documents Monitoring Contributor as the superset that also creates and changes monitoring settings.
Editorial sources (5)
- Azure built-in roles for Monitor →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Roles, permissions, and security in Azure Monitor →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.