Azure Security built-in role

Security Reader

Provides read-oriented access to Microsoft Defender for Cloud recommendations, alerts, security policies, states, Log Analytics workspace data, and related operational information. The built-in definition has no DataActions but is not purely metadata-only: it also includes specific IoT security package-download, manager-activation download, and sensor reset-password download Actions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 39bc4728-0917-49c7-9d2c-d95423bc2eb4

Control-plane actions (14)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the subscription or resource group whose Defender for Cloud posture the principal must inspect. Parent-scope assignments are inherited by all child resources and expose their security state. Management-group scope should be reserved for readers who genuinely require all inheriting subscriptions.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Security Reader to trusted monitoring or audit personnel at the narrowest Defender for Cloud scope. Verify the included IoT download Actions are acceptable; otherwise create a narrower custom reader. Use Security Admin only for approved policy, plan, alert, recommendation, or security-component changes.

Related roles (2)

Editorial sources (5)

Official Microsoft Learn documentation →