Azure Security built-in role
Security Reader
Provides read-oriented access to Microsoft Defender for Cloud recommendations, alerts, security policies, states, Log Analytics workspace data, and related operational information. The built-in definition has no DataActions but is not purely metadata-only: it also includes specific IoT security package-download, manager-activation download, and sensor reset-password download Actions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 39bc4728-0917-49c7-9d2c-d95423bc2eb4
Control-plane actions (14)
Microsoft.Authorization/*/readMicrosoft.Insights/alertRules/readMicrosoft.operationalInsights/workspaces/*/readMicrosoft.Resources/deployments/*/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Security/*/readMicrosoft.IoTSecurity/*/readMicrosoft.Support/*/readMicrosoft.Security/iotDefenderSettings/packageDownloads/actionMicrosoft.Security/iotDefenderSettings/downloadManagerActivation/actionMicrosoft.Security/iotSensors/downloadResetPassword/actionMicrosoft.IoTSecurity/defenderSettings/packageDownloads/actionMicrosoft.IoTSecurity/defenderSettings/downloadManagerActivation/actionMicrosoft.Management/managementGroups/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at the subscription or resource group whose Defender for Cloud posture the principal must inspect. Parent-scope assignments are inherited by all child resources and expose their security state. Management-group scope should be reserved for readers who genuinely require all inheriting subscriptions.
Common use cases (2)
- Allow security operations, audit, risk, or compliance personnel to view Defender for Cloud recommendations, alerts, policies, and security state.
- Inspect IoT security configuration and retrieve the specific packages or reset material permitted by the published definition for an authorized support workflow.
Prerequisites (3)
- Identify the subscriptions or resource groups whose security posture and alert data the principal is authorized to view.
- Confirm whether the principal may receive the IoT package and sensor reset-password download capabilities included in the built-in role; use a custom role if not.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at the target scope.
Best practices (3)
- Assign at the narrowest subscription or resource-group scope and use groups rather than repeated direct user assignments.
- Review the non-read IoT download Actions before treating this as a generic monitoring role.
- Monitor access to alerts, recommendations, package downloads, and reset-password material and review broad inherited assignments regularly.
Security considerations (3)
- Security posture and Log Analytics workspace data can reveal vulnerabilities, attack paths, alerts, policies, resource inventory, workload activity, and defensive gaps that are valuable to an attacker.
- The IoT sensor reset-password and package-download Actions can expose sensitive operational material despite the Reader name.
- The role cannot change Defender for Cloud policy or dismiss alerts and has no DataActions, but its full published authority is more sensitive than ordinary resource metadata read access.
Assignment guidance
Assign Security Reader to trusted monitoring or audit personnel at the narrowest Defender for Cloud scope. Verify the included IoT download Actions are acceptable; otherwise create a narrower custom reader. Use Security Admin only for approved policy, plan, alert, recommendation, or security-component changes.
Related roles (2)
- Security Admin: Microsoft documents Security Admin as adding policy, plan, alert, and recommendation administration to Security Reader visibility.
- Reader: Microsoft documents both Reader and Security Reader for viewing Defender for Cloud information, while the Security Reader definition includes additional security-provider operations.
Editorial sources (5)
- Azure built-in roles for Security →
Supports: Description, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- User roles and permissions - Microsoft Defender for Cloud →
Supports: Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.