Azure Monitor built-in role

Service Health Security Reader

Views sensitive Azure Service Health security-advisory details and the resources impacted by those advisories. The role uses Resource Health control-plane Actions and no DataActions; its published NotAction excludes fetching billing communication details.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 1a928ab0-1fee-43cf-9266-f9d8c22a8ddb

Control-plane actions (11)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (1)

Assignable scopes (1)

Practical scope

Assign at subscription scope to authorize security-advisory impacted-resource information for that subscription. Tenant-level security advisory access uses separately documented tenant roles and permissions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Service Health Security Reader at each subscription where the security operations principal must see sensitive advisory details and impacted resources. Grant remediation roles separately on the affected resources.

Related roles (2)

Editorial sources (5)

Official Microsoft Learn documentation →