Azure Monitor built-in role

Service Health Security Reader

Views sensitive Azure Service Health security-advisory details and the resources impacted by those advisories. The role uses Resource Health control-plane Actions and no DataActions; its published NotAction excludes fetching billing communication details.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 1a928ab0-1fee-43cf-9266-f9d8c22a8ddb

Control-plane actions (11)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (1)

Assignable scopes (1)

Practical scope

Assign at subscription scope to authorize security-advisory impacted-resource information for that subscription. Tenant-level security advisory access uses separately documented tenant roles and permissions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Service Health Security Reader at each subscription where the security operations principal must see sensitive advisory details and impacted resources. Grant remediation roles separately on the affected resources.

Related roles (2)

Common questions

When should I assign the Service Health Security Reader Azure role?

Assign Service Health Security Reader when you need to: Review sensitive Service Health security advisory descriptions, updates, and impacted Azure resources for a subscription.; and Retrieve the impacted-resource list for a security advisory through the Resource Health Events API.. Practical scope: Assign at subscription scope to authorize security-advisory impacted-resource information for that subscription. Tenant-level security advisory access uses separately documented tenant roles and permissions.

What permissions does the Service Health Security Reader Azure role grant?

The role definition grants 11 combined control-plane and data-plane actions. Representative operations include: Microsoft.ResourceHealth/events/action; Microsoft.ResourceHealth/AvailabilityStatuses/read; Microsoft.ResourceHealth/AvailabilityStatuses/current/read; Microsoft.ResourceHealth/Operations/read; Microsoft.ResourceHealth/emergingissues/read; and Microsoft.ResourceHealth/events/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Service Health Security Reader Azure role?

Key considerations when assigning Service Health Security Reader: Security advisory descriptions, updates, tenant identifiers, subscription identifiers, and impacted-resource details are sensitive.; The role provides read and fetch operations for security events but does not grant permissions to remediate the impacted resources.; and Billing communication details are explicitly excluded by the role definition.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →