Azure Monitor built-in role

Monitoring Reader

Views monitoring data and monitoring settings without changing monitored resources or monitoring configuration. The published definition uses broad control-plane read Actions and has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 43d0d8ad-25c7-4714-9337-8ba259a9fe05

Control-plane actions (3)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at a resource, resource group, or subscription according to the monitoring data the principal must inspect. The broad control-plane read permission is inherited by all child resources in the selected scope.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Monitoring Reader at the smallest resource or resource-group scope that covers the monitoring investigation. Add storage, event-hub, or other data access separately only when the task requires those destinations.

Related roles (1)

Common questions

When should I assign the Monitoring Reader Azure role?

Assign Monitoring Reader when you need to: View monitoring dashboards, alert rules, metrics, Activity Log records, diagnostic settings, autoscale settings, and Application Insights data.; and Query authorized Log Analytics data and retrieve workspace table schemas and saved queries for support or operations work.. Practical scope: Assign at a resource, resource group, or subscription according to the monitoring data the principal must inspect. The broad control-plane read permission is inherited by all child resources in the selected scope.

What permissions does the Monitoring Reader Azure role grant?

The role definition grants 3 combined control-plane and data-plane actions. Representative operations include: */read; Microsoft.OperationalInsights/workspaces/search/action; and Microsoft.Support/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Monitoring Reader Azure role?

Key considerations when assigning Monitoring Reader: The role's control-plane read permission exposes resource configuration and monitoring metadata throughout the assigned scope.; Monitoring data can contain sensitive information such as IP addresses and user names.; and The role does not itself grant read access to monitoring data stored in a storage account or streamed to an event hub.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →