Azure Management and governance built-in role

Service Group Reader

Reads preview Azure Service Groups and their connected relationships without changing the hierarchy or assigning roles. It is control-plane read access at the Service Groups provider scope and has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: de754d53-652d-4c75-a67f-1e48d8b49c97

Control-plane actions (2)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign under `/providers/Microsoft.Management/serviceGroups` at the service group branch the principal may inspect. This tenant/provider hierarchy is separate from management groups and subscriptions.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign to portfolio stakeholders or auditors at the service-group branch they need to inspect. Use Contributor only for approved lifecycle changes.

Related roles (2)

Common questions

When should I assign the Service Group Reader Azure role?

Assign Service Group Reader when you need to: Inspect service-group structure and connected relationships for portfolio, governance, or audit work.; and Provide read-only visibility into the preview service hierarchy without lifecycle or delegation authority.. Practical scope: Assign under `/providers/Microsoft.Management/serviceGroups` at the service group branch the principal may inspect. This tenant/provider hierarchy is separate from management groups and subscriptions.

What permissions does the Service Group Reader Azure role grant?

The role definition grants 2 combined control-plane and data-plane actions. Representative operations include: */read; and Microsoft.Authorization/*/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Service Group Reader Azure role?

Key considerations when assigning Service Group Reader: Service-group relationships can reveal the organization's service portfolio and dependencies.; and The role cannot change groups, relationships, role assignments, or workload data.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →