Azure Security built-in role

Security Reader

Provides read-oriented access to Microsoft Defender for Cloud recommendations, alerts, security policies, states, Log Analytics workspace data, and related operational information. The built-in definition has no DataActions but is not purely metadata-only: it also includes specific IoT security package-download, manager-activation download, and sensor reset-password download Actions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 39bc4728-0917-49c7-9d2c-d95423bc2eb4

Control-plane actions (14)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the subscription or resource group whose Defender for Cloud posture the principal must inspect. Parent-scope assignments are inherited by all child resources and expose their security state. Management-group scope should be reserved for readers who genuinely require all inheriting subscriptions.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Security Reader to trusted monitoring or audit personnel at the narrowest Defender for Cloud scope. Verify the included IoT download Actions are acceptable; otherwise create a narrower custom reader. Use Security Admin only for approved policy, plan, alert, recommendation, or security-component changes.

Related roles (2)

Common questions

When should I assign the Security Reader Azure role?

Assign Security Reader when you need to: Allow security operations, audit, risk, or compliance personnel to view Defender for Cloud recommendations, alerts, policies, and security state.; and Inspect IoT security configuration and retrieve the specific packages or reset material permitted by the published definition for an authorized support workflow.. Practical scope: Assign at the subscription or resource group whose Defender for Cloud posture the principal must inspect. Parent-scope assignments are inherited by all child resources and expose their security state. Management-group scope should be reserved for readers who genuinely require all inheriting subscriptions.

What permissions does the Security Reader Azure role grant?

The role definition grants 14 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Insights/alertRules/read; Microsoft.operationalInsights/workspaces/*/read; Microsoft.Resources/deployments/*/read; Microsoft.Resources/subscriptions/resourceGroups/read; and Microsoft.Security/*/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Security Reader Azure role?

Key considerations when assigning Security Reader: Security posture and Log Analytics workspace data can reveal vulnerabilities, attack paths, alerts, policies, resource inventory, workload activity, and defensive gaps that are valuable to an attacker.; The IoT sensor reset-password and package-download Actions can expose sensitive operational material despite the Reader name.; and The role cannot change Defender for Cloud policy or dismiss alerts and has no DataActions, but its full published authority is more sensitive than ordinary resource metadata read access.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →