Azure Management and governance built-in role

Policy Insights Data Writer (Preview)

Preview role that reads Azure Policy assignments, definitions, initiatives, and exemptions and uses Policy Insights DataActions to check resource-component compliance and log component policy events. It does not create policy definitions or assignments.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 66bb4e9e-b016-4a94-8249-4c0511c2be84

Microsoft Learn identifies this role as Preview in its published role name.

Control-plane actions (4)

Data-plane actions (2)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign only to the documented policy component or integration identity at the cluster or resource boundary that reports compliance. Its DataActions write policy event data for resources in scope.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign only to the documented Azure Policy component identity at the governed scope. Preserve the Preview designation, monitor event integrity, and do not grant it to general policy administrators.

Common questions

When should I assign the Policy Insights Data Writer (Preview) Azure role?

Assign Policy Insights Data Writer (Preview) when you need to: Allow an Azure Policy for Kubernetes integration to evaluate resource components against data policies and report policy events.; and Support preview component-level policy compliance reporting without granting policy authoring authority.. Practical scope: Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign only to the documented policy component or integration identity at the cluster or resource boundary that reports compliance. Its DataActions write policy event data for resources in scope.

What permissions does the Policy Insights Data Writer (Preview) Azure role grant?

The role definition grants 6 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/policyassignments/read; Microsoft.Authorization/policydefinitions/read; Microsoft.Authorization/policyexemptions/read; Microsoft.Authorization/policysetdefinitions/read; Microsoft.PolicyInsights/checkDataPolicyCompliance/action; and Microsoft.PolicyInsights/policyEvents/logDataEvents/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Policy Insights Data Writer (Preview) Azure role?

Key considerations when assigning Policy Insights Data Writer (Preview): The DataActions can write component policy events that feed compliance reporting, so a compromised identity could affect governance evidence.; and The role reads policy configuration but cannot author policy definitions or assignments; preview behavior and support can change.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →