Azure General built-in role

Reader

Views Azure resource control-plane information at the assigned scope without changing resources. Reader is broad across resource types but read-only in the Azure management plane.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: acdd72a7-3385-48ef-bd42-f606fba81ae7

Control-plane actions (1)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The built-in definition is available throughout the Azure hierarchy. A Reader assignment applies at the selected management group, subscription, resource group, or resource and is inherited by child scopes. It grants */read in Actions but has no DataActions, so it does not by itself read workload data such as blob contents or secret values.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Use Reader for broad control-plane visibility without modification rights. Choose a narrower service-specific reader when available, keep the scope no broader than the inspection task requires, and add a separate data-plane reader only for explicitly approved data access.

Related roles (1)

Editorial sources (4)

Official Microsoft Learn documentation →