Azure Management and governance built-in role
Policy Insights Data Writer (Preview)
Preview role that reads Azure Policy assignments, definitions, initiatives, and exemptions and uses Policy Insights DataActions to check resource-component compliance and log component policy events. It does not create policy definitions or assignments.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 66bb4e9e-b016-4a94-8249-4c0511c2be84
Control-plane actions (4)
Microsoft.Authorization/policyassignments/readMicrosoft.Authorization/policydefinitions/readMicrosoft.Authorization/policyexemptions/readMicrosoft.Authorization/policysetdefinitions/read
Data-plane actions (2)
Microsoft.PolicyInsights/checkDataPolicyCompliance/actionMicrosoft.PolicyInsights/policyEvents/logDataEvents/action
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Azure RBAC assignments apply at the selected scope and are inherited by child scopes. Keep the assignment at the narrowest resource, resource group, subscription, or management-group boundary that contains the intended resources. Assign only to the documented policy component or integration identity at the cluster or resource boundary that reports compliance. Its DataActions write policy event data for resources in scope.
Common use cases (2)
- Allow an Azure Policy for Kubernetes integration to evaluate resource components against data policies and report policy events.
- Support preview component-level policy compliance reporting without granting policy authoring authority.
Prerequisites (2)
- Use the supported Azure Policy for Kubernetes integration and confirm the feature remains appropriate while the role is in preview.
- The target policy assignments and component reporting path must already be configured.
Best practices (2)
- Assign to the integration identity rather than human users and limit scope to the governed cluster or resource group.
- Monitor policy event volume and reassess the role and workflow before production reliance because the lifecycle marker is Preview.
Security considerations (2)
- The DataActions can write component policy events that feed compliance reporting, so a compromised identity could affect governance evidence.
- The role reads policy configuration but cannot author policy definitions or assignments; preview behavior and support can change.
Assignment guidance
Assign only to the documented Azure Policy component identity at the governed scope. Preserve the Preview designation, monitor event integrity, and do not grant it to general policy administrators.
Editorial sources (6)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Understand Azure Policy for Kubernetes clusters →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Azure Policy assignment structure →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.