Azure Monitor built-in role
Service Health Security Reader
Views sensitive Azure Service Health security-advisory details and the resources impacted by those advisories. The role uses Resource Health control-plane Actions and no DataActions; its published NotAction excludes fetching billing communication details.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 1a928ab0-1fee-43cf-9266-f9d8c22a8ddb
Control-plane actions (11)
Microsoft.ResourceHealth/events/actionMicrosoft.ResourceHealth/AvailabilityStatuses/readMicrosoft.ResourceHealth/AvailabilityStatuses/current/readMicrosoft.ResourceHealth/Operations/readMicrosoft.ResourceHealth/emergingissues/readMicrosoft.ResourceHealth/events/readMicrosoft.ResourceHealth/events/fetchEventDetails/actionMicrosoft.ResourceHealth/events/listSecurityAdvisoryImpactedResources/actionMicrosoft.ResourceHealth/events/impactedResources/readMicrosoft.ResourceHealth/metadata/readMicrosoft.ResourceHealth/potentialoutages/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (1)
Microsoft.ResourceHealth/events/fetchBillingCommunicationDetails/action
Assignable scopes (1)
/
Practical scope
Assign at subscription scope to authorize security-advisory impacted-resource information for that subscription. Tenant-level security advisory access uses separately documented tenant roles and permissions.
Common use cases (2)
- Review sensitive Service Health security advisory descriptions, updates, and impacted Azure resources for a subscription.
- Retrieve the impacted-resource list for a security advisory through the Resource Health Events API.
Prerequisites (2)
- The principal must be responsible for security advisories affecting resources in the target subscription.
- A Service Health security advisory must exist for the subscription before impacted-resource details are available to review.
Best practices (3)
- Assign only on subscriptions for which the principal handles security advisories.
- Use the dedicated role when sensitive advisory access is needed without the broader authority of subscription Owner or Contributor.
- Review subscription-level access when security incident responsibilities or personnel change.
Security considerations (3)
- Security advisory descriptions, updates, tenant identifiers, subscription identifiers, and impacted-resource details are sensitive.
- The role provides read and fetch operations for security events but does not grant permissions to remediate the impacted resources.
- Billing communication details are explicitly excluded by the role definition.
Assignment guidance
Assign Service Health Security Reader at each subscription where the security operations principal must see sensitive advisory details and impacted resources. Grant remediation roles separately on the affected resources.
Related roles (2)
- Owner: Microsoft lists subscription Owner as another role authorized to view sensitive security-advisory details and impacted resources.
- Contributor: Microsoft lists subscription Contributor as another role authorized to view sensitive security-advisory details and impacted resources.
Editorial sources (5)
- Azure built-in roles for Monitor →
Supports: Description, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-16.
- Impacted resources from Azure security advisories →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.