Azure Management and governance built-in role
SRE Agent Standard User
Lets a user chat with Azure SRE Agent, start threads, run diagnostics, upload knowledge documents, and request actions, but not approve actions, delete resources, modify connectors or response plans, manage resource scope, or change agent settings. Agent execution still depends on its managed identity or an Administrator-approved on-behalf-of flow.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 2d84a65a-63b2-4343-bbb6-31105d857bc1
Control-plane actions (3)
Microsoft.Authorization/*/readMicrosoft.Insights/alertRules/readMicrosoft.App/agents/read
Data-plane actions (10)
Microsoft.App/agents/threads/readMicrosoft.App/agents/graph/readMicrosoft.App/agents/memory/readMicrosoft.App/agents/incidentManagement/readMicrosoft.App/agents/threads/writeMicrosoft.App/agents/graph/writeMicrosoft.App/agents/memory/writeMicrosoft.App/agents/scheduledtasks/readMicrosoft.App/agents/scheduledtasks/writeMicrosoft.App/agents/scheduledtasks/delete
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the SRE Agent resource. This controls user interaction with the agent, not the Azure resource groups the agent can access; those roles belong to the agent's user-assigned managed identity.
Common use cases (2)
- Let L1 or L2 engineers and first responders investigate incidents through chat and diagnostics.
- Draft remediation requests for Administrator review without granting approval or agent configuration authority.
Prerequisites (2)
- An SRE Agent must exist with approved knowledge, connectors, run modes, and managed-resource scope.
- Administrators must be available to approve actions that exceed Standard User authority or require OBO.
Best practices (2)
- Use Standard User for responders and keep approvals on a separate Administrator group.
- Start the agent managed identity at read level, review uploaded knowledge, and monitor diagnostic and action requests.
Security considerations (2)
- The user can supply prompts and knowledge and request actions, which can influence an agent operating against production context.
- Standard User cannot approve actions or authorize OBO, and it does not receive the agent managed identity's Azure permissions.
Assignment guidance
Assign to responders at the agent resource. Keep approval, connector, run-mode, settings, and managed-resource changes on Administrator, and manage the agent identity's resource access independently.
Related roles (2)
- SRE Agent Administrator: Reviews and approves actions and manages the agent.
- SRE Agent Reader: Read-only alternative without chat or diagnostics.
Editorial sources (6)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- User roles and permissions in Azure SRE Agent →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Agent permissions in Azure SRE Agent →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.