Azure Management and governance built-in role
Service Group Reader
Reads preview Azure Service Groups and their connected relationships without changing the hierarchy or assigning roles. It is control-plane read access at the Service Groups provider scope and has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: de754d53-652d-4c75-a67f-1e48d8b49c97
Control-plane actions (2)
*/readMicrosoft.Authorization/*/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/providers/Microsoft.Management/serviceGroups
Practical scope
Assign under `/providers/Microsoft.Management/serviceGroups` at the service group branch the principal may inspect. This tenant/provider hierarchy is separate from management groups and subscriptions.
Common use cases (2)
- Inspect service-group structure and connected relationships for portfolio, governance, or audit work.
- Provide read-only visibility into the preview service hierarchy without lifecycle or delegation authority.
Prerequisites (2)
- The Service Groups preview and target service-group branch must exist.
- Confirm that the principal is authorized to view all connected services in the selected branch.
Best practices (2)
- Assign at a branch instead of the root when tenant-wide visibility is unnecessary.
- Reassess the role and information model while the service remains in preview.
Security considerations (2)
- Service-group relationships can reveal the organization's service portfolio and dependencies.
- The role cannot change groups, relationships, role assignments, or workload data.
Assignment guidance
Assign to portfolio stakeholders or auditors at the service-group branch they need to inspect. Use Contributor only for approved lifecycle changes.
Related roles (2)
- Service Group Contributor: Adds service-group and relationship lifecycle management.
- Service Group Administrator: Adds conditioned Service Group role delegation.
Editorial sources (5)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- What are Azure Service Groups? →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.