Azure Monitor built-in role
Service Health Security Reader
Views sensitive Azure Service Health security-advisory details and the resources impacted by those advisories. The role uses Resource Health control-plane Actions and no DataActions; its published NotAction excludes fetching billing communication details.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 1a928ab0-1fee-43cf-9266-f9d8c22a8ddb
Control-plane actions (11)
Microsoft.ResourceHealth/events/actionMicrosoft.ResourceHealth/AvailabilityStatuses/readMicrosoft.ResourceHealth/AvailabilityStatuses/current/readMicrosoft.ResourceHealth/Operations/readMicrosoft.ResourceHealth/emergingissues/readMicrosoft.ResourceHealth/events/readMicrosoft.ResourceHealth/events/fetchEventDetails/actionMicrosoft.ResourceHealth/events/listSecurityAdvisoryImpactedResources/actionMicrosoft.ResourceHealth/events/impactedResources/readMicrosoft.ResourceHealth/metadata/readMicrosoft.ResourceHealth/potentialoutages/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (1)
Microsoft.ResourceHealth/events/fetchBillingCommunicationDetails/action
Assignable scopes (1)
/
Practical scope
Assign at subscription scope to authorize security-advisory impacted-resource information for that subscription. Tenant-level security advisory access uses separately documented tenant roles and permissions.
Common use cases (2)
- Review sensitive Service Health security advisory descriptions, updates, and impacted Azure resources for a subscription.
- Retrieve the impacted-resource list for a security advisory through the Resource Health Events API.
Prerequisites (2)
- The principal must be responsible for security advisories affecting resources in the target subscription.
- A Service Health security advisory must exist for the subscription before impacted-resource details are available to review.
Best practices (3)
- Assign only on subscriptions for which the principal handles security advisories.
- Use the dedicated role when sensitive advisory access is needed without the broader authority of subscription Owner or Contributor.
- Review subscription-level access when security incident responsibilities or personnel change.
Security considerations (3)
- Security advisory descriptions, updates, tenant identifiers, subscription identifiers, and impacted-resource details are sensitive.
- The role provides read and fetch operations for security events but does not grant permissions to remediate the impacted resources.
- Billing communication details are explicitly excluded by the role definition.
Assignment guidance
Assign Service Health Security Reader at each subscription where the security operations principal must see sensitive advisory details and impacted resources. Grant remediation roles separately on the affected resources.
Related roles (2)
- Owner: Microsoft lists subscription Owner as another role authorized to view sensitive security-advisory details and impacted resources.
- Contributor: Microsoft lists subscription Contributor as another role authorized to view sensitive security-advisory details and impacted resources.
Common questions
When should I assign the Service Health Security Reader Azure role?
Assign Service Health Security Reader when you need to: Review sensitive Service Health security advisory descriptions, updates, and impacted Azure resources for a subscription.; and Retrieve the impacted-resource list for a security advisory through the Resource Health Events API.. Practical scope: Assign at subscription scope to authorize security-advisory impacted-resource information for that subscription. Tenant-level security advisory access uses separately documented tenant roles and permissions.
What permissions does the Service Health Security Reader Azure role grant?
The role definition grants 11 combined control-plane and data-plane actions. Representative operations include: Microsoft.ResourceHealth/events/action; Microsoft.ResourceHealth/AvailabilityStatuses/read; Microsoft.ResourceHealth/AvailabilityStatuses/current/read; Microsoft.ResourceHealth/Operations/read; Microsoft.ResourceHealth/emergingissues/read; and Microsoft.ResourceHealth/events/read. Review the permission sections above for the complete definition and exclusions.
What are the security risks of the Service Health Security Reader Azure role?
Key considerations when assigning Service Health Security Reader: Security advisory descriptions, updates, tenant identifiers, subscription identifiers, and impacted-resource details are sensitive.; The role provides read and fetch operations for security events but does not grant permissions to remediate the impacted resources.; and Billing communication details are explicitly excluded by the role definition.. Follow the assignment guidance above and use the narrowest practical scope.
Editorial sources (5)
- Azure built-in roles for Monitor →
Supports: Description, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-16.
- Impacted resources from Azure security advisories →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.